Junglewise Threat Intelligence

CVE-2026-57797: ThemeMove EduMall missing authorization in WordPress theme

CVE-2026-57797 · Severity: medium · CVSS 4.3 · Published 2026-07-13

Vendors: ThemeMove.

Executive brief

ThemeMove EduMall, a WordPress theme used for educational and learning management websites, contains a security flaw in its access control settings. This vulnerability allows logged-in users with low-level permissions (such as students or subscribers) to perform actions they should not be authorized to do. While the impact is rated as low, it could lead to unauthorized changes or disruptions to the site's functionality.

Technical details

A missing authorization vulnerability (CWE-862) exists in the ThemeMove EduMall theme for WordPress. The issue stems from incorrectly configured access control security levels within the theme's functions. An attacker authenticated with basic 'Subscriber' or 'Student' privileges can exploit this lack of server-side authorization checks to execute functions or access features intended for higher-privileged users. The vulnerability is present in versions up to and including 4.5.1. A fix is available in version 4.5.2.

Affected products

  • ThemeMove EduMall <= 4.5.1

Timeline

  • 2026-03-09: other: Reported by Nguyen Ba Khanh
  • 2026-07-02: disclosed: Initial disclosure by Patchstack
  • 2026-07-13: advisory: NVD publication date
  • 2026-07-13: patched: Patch confirmed available in version 4.5.2

References