Description
Missing Authorization vulnerability in ThemeIsle Hestia allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Hestia: from n/a through 3.2.10.
No analysis available yet.
Remediation
Vendor Solution
Update the WordPress Hestia theme to the latest available version (at least 3.2.11).
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-21690 | Missing Authorization vulnerability in ThemeIsle Hestia allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Hestia: from n/a through 3.2.10. |
References
History
Wed, 16 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
Wed, 16 Jul 2025 10:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Missing Authorization vulnerability in ThemeIsle Hestia allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Hestia: from n/a through 3.2.10. | |
| Title | WordPress Hestia theme <= 3.2.10 - Broken Access Control Vulnerability | |
| Weaknesses | CWE-862 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Patchstack
Published:
Updated: 2025-07-16T14:39:34.319Z
Reserved: 2025-07-16T08:51:03.831Z
Link: CVE-2025-53986
No data.
Status : Awaiting Analysis
Published: 2025-07-16T11:15:26.533
Modified: 2025-07-16T14:58:59.837
Link: CVE-2025-53986
No data.
OpenCVE Enrichment
Updated: 2025-07-21T15:17:37Z
Weaknesses
EUVD