Executive brief
Homlisti is a WordPress theme used to create property listing and real estate websites. A broken access control vulnerability in versions 3.1.2 and earlier allows users with subscriber-level permissions to view or access content and perform actions they should not be allowed to, such as viewing other users' private data or properties.
Technical details
The vulnerability is a broken access control flaw (CWE-639) in the Homlisti WordPress theme versions up to 3.1.2. It allows authenticated subscribers to bypass authorization checks and access restricted pages or perform unauthorized actions. The attack requires a valid subscriber account but no additional privilege escalation; the flaw exists because the theme fails to properly validate user permissions before granting access to sensitive functionality. No official patch has been released as of the advisory date, though Patchstack has provided a WAF rule for mitigation.
Affected products
- Homlisti Homlisti <=3.1.2
Timeline
- 2026-08-20: disclosed
- 2026-01-14: reported