Description
Unauthenticated Broken Access Control in Altair <= 5.2.2 versions.
Published: 2026-08-20
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Affected versions of the Altair theme for WordPress allow an attacker to perform actions that normally require authentication because the theme fails to enforce proper access control on privileged operations. The vulnerability falls under CWE‑862, indicating that authorization checks are missing or insufficient. If exploited, an unauthenticated user could perform functions that should be limited to site administrators, potentially modifying site content or configurations.

Affected Systems

ThemeGoods Altair theme versions up to and including 5.2.2 are susceptible to this flaw. The vulnerability affects any WordPress installation that has the Altair theme activated and uses one of the mentioned versions. No specific WordPress core versions are listed as affected, but the theme exists on all common WordPress setups where it is installed.

Risk and Exploitability

The CVSS base score of 6.5 marks this as a medium severity issue, and the EPSS score is not available, so the likelihood of exploitation cannot be quantified from the data provided. The vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is through web requests to theme‑related endpoints that do not perform authentication checks, enabling an attacker to carry out privileged actions without credentials. Such exploitation would compromise the integrity of site content and could serve as a foothold for further attacks.

Generated by OpenCVE AI on August 20, 2026 at 21:51 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the Altair theme to a version newer than 5.2.2 as soon as a patched release becomes available.
  • If an update is not immediately possible, remove or deactivate the Altair theme to prevent exposed functionality from being used.
  • Configure the WordPress file permissions to ensure that theme files are not writable by unauthorized users, reducing the risk of future exploitation.

Generated by OpenCVE AI on August 20, 2026 at 21:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 20 Aug 2026 14:15:00 +0000

Type Values Removed Values Added
First Time appeared Themegoods
Themegoods altair
Wordpress
Wordpress wordpress
Vendors & Products Themegoods
Themegoods altair
Wordpress
Wordpress wordpress

Thu, 20 Aug 2026 12:15:00 +0000

Type Values Removed Values Added
Description Unauthenticated Broken Access Control in Altair <= 5.2.2 versions.
Title WordPress Altair theme <= 5.2.2 - Broken Access Control vulnerability
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L'}


Subscriptions

Themegoods Altair
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-08-20T15:43:51.353Z

Reserved: 2025-07-16T08:51:16.734Z

Link: CVE-2025-53999

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-08-20T12:16:32.027

Modified: 2026-08-20T16:17:06.010

Link: CVE-2025-53999

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-20T22:00:05Z

Weaknesses