Description
Missing Authorization vulnerability in Linethemes NanoCare allows Exploiting Incorrectly Configured Access Control Security Levels.

This issue affects NanoCare: from n/a before 1.2.2.
Published: 2026-05-25
Score: 5.4 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a missing authorization flaw in the Linethemes NanoCare WordPress theme. It allows an attacker to bypass the intended security controls and access administrative or restricted areas of the site. The flaw is cataloged as CWE-862, indicating that the application incorrectly implements access control, potentially enabling privilege escalation or unauthorized data exposure. No code execution or DoS impact is described, but the breach could let an attacker read or modify site content, settings, or user data.

Affected Systems

The issue affects the Linethemes NanoCare WordPress theme versions prior to 1.2.2. Any WordPress installation that has this theme deployed and has not upgraded to the fixed version is vulnerable. The problem is confined to the theme implementation and does not require additional components, although all systems running the theme are potentially impacted.

Risk and Exploitability

The CVSS score of 5.4 places the vulnerability in the moderate severity range, indicating a non-trivial risk but not the highest. EPSS data is not available, so no exploitation probability can be assigned from the database. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is through web requests to the affected theme’s administrative endpoints, since the flaw involves incorrectly configured access control. An attacker who can reach those endpoints may bypass authentication and perform privileged actions against the WordPress site.

Generated by OpenCVE AI on May 26, 2026 at 00:21 UTC.

Remediation

Vendor Solution

Update the WordPress NanoCare Theme to the latest available version (at least 1.2.2).


OpenCVE Recommended Actions

  • Upgrade the NanoCare theme to version 1.2.2 or newer as required by the vendor.
  • Remove or replace any custom code or plugins that depend on the older theme functionality until the update can be applied.
  • Implement network restrictions—such as IP whitelisting or WAF rules—to block direct access to the theme’s administrative pages until the theme is updated.

Generated by OpenCVE AI on May 26, 2026 at 00:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 25 May 2026 23:00:00 +0000

Type Values Removed Values Added
Description Missing Authorization vulnerability in Linethemes NanoCare allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects NanoCare: from n/a before 1.2.2.
Title WordPress NanoCare theme < 1.2.2 - Broken Access Control vulnerability
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-05-25T22:42:13.517Z

Reserved: 2026-03-12T11:11:09.667Z

Link: CVE-2026-32389

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-26T00:30:26Z

Weaknesses