Junglewise Threat Intelligence

CVE-2026-65476: uxper Civi theme broken access control

CVE-2026-65476 · Severity: medium · CVSS 5.3 · Published 2026-07-23

Executive brief

The Civi theme for WordPress, which is used to build job board and recruitment websites, contains a security flaw that allows unauthorized users to perform actions they should not have access to. Because the software fails to properly check for permissions, an attacker could potentially modify certain site settings or data without logging in. This could lead to unauthorized changes to the website's content or configuration, though it is currently rated as a medium-risk issue.

Technical details

A broken access control vulnerability exists in the uxper Civi theme for WordPress (versions <= 2.2.4) due to missing authorization (CWE-862) or nonce checks. This flaw allows an unauthenticated remote attacker to execute functions that should be restricted to higher-privileged users. The attack vector is network-based and requires no user interaction or prior authentication. While the specific impacted functions are not detailed in the advisory, the CVSS score of 5.3 suggests the impact is limited to unauthorized data integrity changes (Integrity: Low) without affecting confidentiality or availability. As of the latest report, no official patch is available.

Affected products

  • uxper Civi <= 2.2.4

Timeline

  • 2026-01-06: disclosed: Vulnerability reported by researcher João Pedro S Alcântara
  • 2026-07-22: advisory: Patchstack published the vulnerability advisory
  • 2026-07-23: other: CVE record published in NVD

References