Description
Missing Authorization vulnerability in wproyal Bard bard allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Bard: from n/a through <= 2.229.
Published: 2026-01-22
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A missing authorization check in the Bard WordPress theme allows an attacker to exploit incorrectly configured access control settings. The weakness stems from a flaw in permission handling (CWE-862) and enables users who should not have certain capabilities to perform privileged actions. While the vulnerability does not provide remote code execution or full system takeover, it can be used to expose or modify sensitive content, degrade site integrity, or create a foothold for further attacks. The attack vector is inferred because it is not explicitly detailed in the CVE description.

Affected Systems

WordPress sites using the Bard theme from any version up to and including 2.229 are impacted. This includes installations by the vendor wproyal. The vulnerability is present in all pre-2.230 builds without any additional configuration.

Risk and Exploitability

The CVSS score of 4.3 indicates a moderate severity, and the EPSS score of less than 1% suggests a low probability of exploitation at the time of analysis. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires the attacker to have access to a user account that is incorrectly granted higher privileges or to manipulate access control levels exposed by configuration errors. Once exploited, the attacker can access administrative functions such as content editing, plugin installation, or user management, potentially compromising the entire site.

Generated by OpenCVE AI on April 29, 2026 at 21:44 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the Bard theme to the latest release that is newer than version 2.229.
  • Revoke any accidental over-privileged user accounts and ensure roles are assigned only the capabilities required for their responsibilities.
  • Review the theme’s configuration and WordPress role settings to confirm that privileged actions are no longer exposed to non‑admin users.

Generated by OpenCVE AI on April 29, 2026 at 21:44 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 27 Apr 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}

cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'}


Mon, 26 Jan 2026 23:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 23 Jan 2026 16:45:00 +0000

Type Values Removed Values Added
First Time appeared Wordpress
Wordpress wordpress
Vendors & Products Wordpress
Wordpress wordpress

Thu, 22 Jan 2026 23:00:00 +0000

Type Values Removed Values Added
Description Missing Authorization vulnerability in wproyal Bard bard allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Bard: from n/a through <= 2.229.
Title WordPress Bard theme <= 2.229 - Broken Access Control vulnerability
Weaknesses CWE-862
References

Subscriptions

Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:14:08.705Z

Reserved: 2025-10-24T14:25:34.658Z

Link: CVE-2025-63018

cve-icon Vulnrichment

Updated: 2026-01-26T21:56:33.616Z

cve-icon NVD

Status : Deferred

Published: 2026-01-22T17:15:59.540

Modified: 2026-04-27T19:16:18.233

Link: CVE-2025-63018

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-29T21:45:20Z

Weaknesses