Description
Missing Authorization vulnerability in pressmaximum Customify customify-theme allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Customify: from n/a through <= 0.4.8.
Published: 2025-05-19
Score: 5.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability is a missing authorization flaw in the pressmaximum Customify WordPress theme that allows an attacker to exploit incorrectly configured access control security levels. The weakness, classified as CWE‑862, can enable an unauthorized user to access or manipulate privileged functions within the theme, potentially leading to unauthorized data disclosure, modification, or other security impacts. The CVSS score of 5.4 indicates a moderate severity level.

Affected Systems

WordPress installations that use the pressmaximum Customify theme version 0.4.8 or earlier are affected.

Risk and Exploitability

The exposure is moderate, with an EPSS score of less than 1 % and no listing in the CISA KEV catalog. Exploitation appears to be achievable through the theme’s administrative interfaces or other exposed parts of the WordPress site that rely on the Customify theme’s access controls. An attacker who can interact with these interfaces could gain unauthorized actions or data access without needing administrative credentials, though the exact attack path is not fully detailed in the official description.

Generated by OpenCVE AI on May 1, 2026 at 08:23 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Customify theme to a version newer than 0.4.8.
  • If an upgrade is not feasible, disable or remove the Customify theme from the WordPress installation.
  • Review the theme’s access control settings and any custom admin pages to ensure that proper authorization checks are enforced and consider moving sensitive functionality outside of the theme.

Generated by OpenCVE AI on May 1, 2026 at 08:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-27730 Missing Authorization vulnerability in PressMaximum Customify allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Customify: from n/a through 0.4.8.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Missing Authorization vulnerability in PressMaximum Customify allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Customify: from n/a through 0.4.8. Missing Authorization vulnerability in pressmaximum Customify customify-theme allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Customify: from n/a through <= 0.4.8.
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L'}


Tue, 20 May 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 19 May 2025 17:00:00 +0000

Type Values Removed Values Added
Description Missing Authorization vulnerability in PressMaximum Customify allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Customify: from n/a through 0.4.8.
Title WordPress Customify theme <= 0.4.8 - Broken Access Control vulnerability
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L'}


Subscriptions

Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:11:43.806Z

Reserved: 2025-02-17T11:51:01.643Z

Link: CVE-2025-26920

cve-icon Vulnrichment

Updated: 2025-05-20T14:06:44.894Z

cve-icon NVD

Status : Deferred

Published: 2025-05-19T17:15:23.703

Modified: 2026-06-17T09:02:36.373

Link: CVE-2025-26920

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-01T08:30:12Z

Weaknesses