Executive brief
A security vulnerability exists in the Manual WordPress theme, which is used to build documentation and knowledge base websites. An unauthorized person could bypass security restrictions to access sensitive information that should be protected. This could lead to the exposure of private documentation or internal company data stored within the knowledge base.
Technical details
A Broken Access Control vulnerability (CWE-862: Missing Authorization) exists in the Manual - Documentation, Knowledge Base & Education WordPress Theme through version 7.5.4. The flaw allows an unauthenticated remote attacker to bypass authorization checks due to missing validation in theme functions. According to the CVSS vector, this results in a high impact on confidentiality (C/H) but no impact on integrity or availability. As of the advisory date, no official patch has been released by the developer, and the vulnerability is considered difficult to mitigate via standard virtual patching.
Affected products
- pixelacehq Manual - Documentation, Knowledge Base & Education WordPress Theme <= 7.5.4
Timeline
- 2026-06-22: disclosed: Reported by researcher ed32.dll
- 2026-07-23: advisory: Published by Patchstack and NVD