Description
Missing Authorization vulnerability in WofficeIO Woffice allows Exploiting Incorrectly Configured Access Control Security Levels.

This issue affects Woffice: from n/a before 5.4.33.
Published: 2026-07-01
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability in the WordPress Woffice theme before version 5.4.33 is a missing authorization flaw that permits users to bypass intended security levels. An attacker can exploit this to access or modify content that should be restricted, effectively gaining elevated privileges within the site. The weakness is identified as CWE‑862 and results in unauthorized read, write, or administrative actions.

Affected Systems

Affected are deployments of the Woffice theme supplied by WofficeIO. Any installation of the theme older than version 5.4.33 is vulnerable. No specific configuration thresholds are mentioned; the issue exists across all deployed instances until the patch is applied.

Risk and Exploitability

The CVSS base score of 5.3 indicates moderate severity. No EPSS score is available and the vulnerability is not listed in CISA KEV. The attack vector is inferred to be remote through the web interface, as the flaw exists in the theme’s access control logic. Exploitation requires the attacker to reach a page or action that relies on the broken authorization, so a user with any browser access to those pages can benefit. Given the lack of a published exploit, the risk remains moderate but should not be ignored.

Generated by OpenCVE AI on July 1, 2026 at 12:46 UTC.

Remediation

Vendor Solution

Update the WordPress Woffice theme to the latest available version (at least 5.4.33).


OpenCVE Recommended Actions

  • Apply the latest Woffice theme update (at least version 5.4.33).
  • If the update cannot be applied immediately, disable the theme or prevent it from being activated in the production environment to block exploitation.
  • Review and tighten user role permissions so that only trusted accounts can access theme‑dependent functionalities until the patch is installed.

Generated by OpenCVE AI on July 1, 2026 at 12:46 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 01 Jul 2026 11:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 01 Jul 2026 09:30:00 +0000

Type Values Removed Values Added
Description Missing Authorization vulnerability in WofficeIO Woffice allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Woffice: from n/a before 5.4.33.
Title WordPress Woffice theme < 5.4.33 - Broken Access Control vulnerability
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-07-01T10:22:34.470Z

Reserved: 2026-02-19T09:52:32.857Z

Link: CVE-2026-27435

cve-icon Vulnrichment

Updated: 2026-07-01T10:22:31.570Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-01T13:00:15Z

Weaknesses