Description
Missing Authorization vulnerability in wpradiant Chocolate House chocolate-house allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Chocolate House: from n/a through <= 1.1.5.
Published: 2026-03-13
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Broken Access Control
Action: Update Theme
AI Analysis

Impact

This vulnerability is a Missing Authorization flaw in the wpradiant Chocolate House WordPress theme. Key detail from the description: "Missing Authorization vulnerability ... allows Exploiting Incorrectly Configured Access Control Security Levels". Because it is a broken access control problem (CWE-862), an attacker may gain unauthorized access to functionality that should be restricted. The description does not explicitly state which functions are exposed or the consequences, so it is unclear whether an attacker could modify content, upload files, or view sensitive data; these are not confirmed by the supplied data.

Affected Systems

The affected product is the WordPress Chocolate House theme from vendor wpradiant. The CVE impact text shows that the issue applies to all releases from the first release through version 1.1.5, as noted: "Chocolate House: from n/a through <= 1.1.5". Therefore any site running Chocolate House 1.1.5 or earlier is affected.

Risk and Exploitability

The CVSS score of 5.3 indicates a moderate risk. The EPSS score is less than 1%, indicating a low chance of exploitation currently. The vulnerability is not listed in the CISA KEV catalog. The attack vector is not explicitly provided in the description; the likely route is through web requests to the theme’s administrative paths, but this is inferred rather than confirmed by the available information.

Generated by OpenCVE AI on March 19, 2026 at 16:20 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Chocolate House theme to a version newer than 1.1.5. If an upgrade is not immediately possible, restrict access to the theme’s administrative functionality so only privileged users can use it. Check the vendor’s website or the theme’s repository for any future updates or official patches.

Generated by OpenCVE AI on March 19, 2026 at 16:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 16 Mar 2026 10:15:00 +0000

Type Values Removed Values Added
First Time appeared Wordpress
Wordpress wordpress
Wpradiant
Wpradiant chocolate House
Vendors & Products Wordpress
Wordpress wordpress
Wpradiant
Wpradiant chocolate House

Fri, 13 Mar 2026 19:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 13 Mar 2026 12:00:00 +0000

Type Values Removed Values Added
Description Missing Authorization vulnerability in wpradiant Chocolate House chocolate-house allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Chocolate House: from n/a through <= 1.1.5.
Title WordPress Chocolate House theme <= 1.1.5 - Broken Access Control vulnerability
Weaknesses CWE-862
References

Subscriptions

Wordpress Wordpress
Wpradiant Chocolate House
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-01T14:15:56.966Z

Reserved: 2026-03-12T11:10:47.068Z

Link: CVE-2026-32350

cve-icon Vulnrichment

Updated: 2026-03-13T18:44:56.703Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-03-13T19:54:46.927

Modified: 2026-03-16T14:53:46.157

Link: CVE-2026-32350

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-03-23T09:59:06Z

Weaknesses