Executive brief
The Fascinate theme for WordPress contains a security flaw where it fails to properly verify if a user has permission to perform certain actions. This could allow an unauthorized person to bypass security controls and make unauthorized changes to the website's configuration or content. Because the theme is no longer being updated, site owners are advised to replace it with a supported alternative to maintain site integrity.
Technical details
A Broken Access Control vulnerability (CWE-862: Missing Authorization) exists in the themebeez Fascinate theme for WordPress through version 1.1.5. The flaw stems from a lack of proper authorization or nonce checks in functions intended for higher-privileged users. An unauthenticated remote attacker can exploit this to execute actions that should be restricted, potentially altering site settings or content. As of the advisory date, no official patch is available, and the theme is considered end-of-life; users are encouraged to migrate to a different theme.
Affected products
- themebeez Fascinate <= 1.1.5
Timeline
- 2026-01-14: disclosed: Reported by Legion Hunter
- 2026-07-02: advisory: Initial advisory published by Patchstack
- 2026-07-13: advisory: CVE published to NVD dataset