Junglewise Threat Intelligence

CVE-2026-65530: Templatespare TemplateSpare broken access control

CVE-2026-65530 · Severity: medium · CVSS 4.3 · Published 2026-07-23

Executive brief

TemplateSpare is a WordPress plugin used for managing website templates. A security flaw allows users with basic 'Subscriber' accounts to bypass security checks and perform actions they should not be authorized to access. While the impact is considered low, it could allow unauthorized users to view or interact with restricted site features.

Technical details

A broken access control vulnerability exists in the TemplateSpare plugin for WordPress (versions 4.2.2 and below) due to missing authorization (CWE-862) in certain functions. An attacker authenticated with low-level 'Subscriber' privileges can exploit this over the network without user interaction. This allows the attacker to execute actions or access data that should be restricted to higher-privileged users. As of the advisory date, no official patch has been released.

Affected products

  • Templatespare TemplateSpare <= 4.2.2

Timeline

  • 2026-06-10: other: Reported by researcher Ananda Dhakal
  • 2026-07-23: disclosed: Vulnerability published by Patchstack

References

Related threats