Junglewise Threat Intelligence

CVE-2026-77997: YOOtheme Pro privilege escalation via access control bypass

CVE-2026-77997 · Severity: info · Published 2026-08-25

Vendors: YOOtheme.

Executive brief

YOOtheme Pro is a website builder extension for Joomla and WordPress. A missing access check vulnerability allows users with template editing permissions to view information about arbitrary modules without having the required module management permissions, potentially exposing sensitive module configuration or administrative details not intended for their role.

Technical details

This is an authorization/access control bypass vulnerability (CWE-276) in YOOtheme Pro versions 1.0.0 through 5.0.41. The vulnerability exists in the module information retrieval logic, where a missing or insufficient access check allows authenticated users with com_template editing permissions to retrieve sensitive information about arbitrary modules without requiring com_modules permissions. The attack requires valid Joomla authentication but exploits a privilege escalation flaw where granular permission boundaries are not enforced. An attacker can leverage com_template permissions to access module metadata and configuration details beyond their assigned role. A patch or updated version should implement proper permission checks before exposing module information.

Affected products

  • YOOtheme Pro 1.0.0 to 5.0.41

Timeline

  • 2026-08-25: disclosed

References