Executive brief
The Photography theme for WordPress, used by photographers to showcase portfolios, contains a security flaw that allows unauthorized individuals to perform actions they should not have access to. An attacker could potentially modify certain settings or data without needing to log in. While the impact is currently rated as medium, it could affect the integrity of the website's content or configuration.
Technical details
The Photography theme for WordPress (versions up to and including 7.7.6) suffers from a broken access control vulnerability due to missing authorization checks (CWE-862). This flaw allows an unauthenticated remote attacker to execute functions or modify data that should be restricted to administrative users. The vulnerability is exploitable over the network without any user interaction. As of the latest advisory, no official patch has been released by the vendor, ThemeGoods. The CVSS score of 5.3 reflects that while the integrity of the system can be impacted, there is no direct impact on confidentiality or availability.
Affected products
- ThemeGoods Photography Theme <= 7.7.6
Timeline
- 2026-01-29: other: Reported by researcher Phat RiO
- 2026-07-22: advisory: Initial advisory published by Patchstack
- 2026-07-23: disclosed: CVE published in NVD