Executive brief
The Starter Templates WordPress plugin contains an access control flaw that allows contributors (low-privilege users) to view or access data belonging to other users by manipulating object identifiers in URLs. While the vulnerability requires authenticated contributor-level access, it could expose sensitive site data or configuration information created by other users, potentially compromising confidentiality or providing reconnaissance for further attacks.
Technical details
The vulnerability is an Insecure Direct Object Reference (IDOR) in the Starter Templates plugin versions up to 4.7.5. A contributor-level authenticated user can modify ID parameters in URLs to access objects or data belonging to other users, bypassing authorization checks. The attack requires authentication as a contributor role but does not require additional user interaction. An attacker can enumerate and retrieve data that should be restricted to its owner, such as templates, configurations, or metadata. The issue has been patched in version 4.7.6 and later.
Affected products
- Brainstorm Force Starter Templates <=4.7.5
Timeline
- 2026-08-28: disclosed: Reported to Patchstack
- 2026-09-10: advisory: Published by Patchstack
- 2026-09-10: patched: Patched in version 4.7.6