Executive brief
AnalogWP Style Kits, a WordPress plugin used for managing site design and templates, contains a security flaw that allows users with low-level 'Contributor' permissions to perform actions they should not be authorized to do. This could allow an internal user to modify site styles or configurations, potentially impacting the website's appearance or operational integrity. While the risk is considered medium, it requires an attacker to already have a valid account on the site.
Technical details
The AnalogWP Style Kits plugin for WordPress (versions 2.6.5 and below) is vulnerable to broken access control due to missing authorization checks (CWE-862). This vulnerability allows an authenticated attacker with 'Contributor' level privileges to bypass intended access restrictions and execute functions or modify settings typically reserved for higher-privileged users. The attack is reachable over the network without user interaction, provided the attacker has valid low-level credentials. As of the advisory date, no official patch has been confirmed, though users are advised to monitor for updates from AnalogWP.
Affected products
- AnalogWP Style Kits <= 2.6.5
Timeline
- 2026-01-21: other: Vulnerability reported by researcher
- 2026-07-22: advisory: Advisory published by Patchstack
- 2026-07-23: disclosed: CVE published to NVD