Description
Subscriber Broken Access Control in Style Kits <= 2.6.5 versions.
Published: 2026-08-24
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized Data Access
Action: Update Plugin
AI Analysis

Impact

The WordPress Style Kits plugin (versions up to 2.6.5) has a broken access control flaw that allows users with subscriber level privileges to view or modify style kits belonging to other subscribers. This flaw does not provide remote code execution or privilege escalation beyond the plugin’s scope but may expose proprietary design information and allow unwanted alterations to site styling. The weakness is assignable to CWE-862.

Affected Systems

AnalogWP Style Kits plugin, all releases up to and including version 2.6.5.

Risk and Exploitability

The CVSS score of 6.5 indicates a moderate severity vulnerability. No EPSS data is available, so the likelihood of exploitation cannot be quantified from this metric. The vulnerability is not currently listed in the CISA KEV catalog. Based on the description, the attack path requires an authenticated subscriber account; the attacker can access the plugin’s front‑end or API endpoints to read or change other users’ style kits. No special environment or pre‑conditions beyond normal WordPress operation are documented, and there is no evidence of exploitation from unauthenticated users.

Generated by OpenCVE AI on August 24, 2026 at 22:47 UTC.

Remediation

Vendor Solution

Update the WordPress Style Kits Plugin to the latest available version (at least 2.6.6).


OpenCVE Recommended Actions

  • Apply the WordPress Style Kits Plugin update to version 2.6.6 or later, which removes the broken access control flaw.
  • Revoke or adjust subscriber role permissions to limit their ability to view or modify other users’ style kits.
  • Audit existing style kits for unauthorized edits and reassign ownership or correct any changes made prior to the patch.

Generated by OpenCVE AI on August 24, 2026 at 22:47 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 25 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 24 Aug 2026 23:45:00 +0000

Type Values Removed Values Added
First Time appeared Analogwp
Analogwp style Kits
Wordpress
Wordpress wordpress
Vendors & Products Analogwp
Analogwp style Kits
Wordpress
Wordpress wordpress

Mon, 24 Aug 2026 21:45:00 +0000

Type Values Removed Values Added
Description Subscriber Broken Access Control in Style Kits <= 2.6.5 versions.
Title WordPress Style Kits plugin <= 2.6.5 - Broken Access Control vulnerability
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N'}


Subscriptions

Analogwp Style Kits
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-08-25T19:23:25.508Z

Reserved: 2026-02-19T09:51:48.838Z

Link: CVE-2026-27364

cve-icon Vulnrichment

Updated: 2026-08-25T18:32:41.120Z

cve-icon NVD

Status : Deferred

Published: 2026-08-24T22:16:51.380

Modified: 2026-08-26T16:19:05.917

Link: CVE-2026-27364

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-24T23:30:16Z

Weaknesses