Description
Missing Authorization vulnerability in linethemes SmartFix smartfix allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects SmartFix: from n/a through < 1.2.4.
Published: 2026-03-13
Score: 5.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized Access
Action: Immediate Patch
AI Analysis

Impact

The SmartFix theme contains a missing authorization flaw (CWE‑862) that allows an attacker to bypass properly configured access control levels. By exploiting this flaw, an unauthenticated or low‑privilege user can gain unexpected access to administrative functions or alter website content, thereby compromising the integrity and confidentiality of the WordPress site. This issue is identified as a broken access control vulnerability that enables unauthorized users to perform actions normally restricted to site administrators. The vulnerability can allow modification of theme settings, insertion of malicious code, or other actions that could facilitate further exploitation of the site. The flaw is present in all releases of SmartFix up to, but not including, version 1.2.4. The CVSS score is 5.4, indicating moderate severity, while the EPSS score is below 1%, suggesting a low likelihood of widespread exploitation. It is not listed in the CISA known exploited vulnerability catalog. The available description does not explicitly state the attack vector; however, based on the nature of the flaw and typical WordPress theme behavior, the attack is inferred to be remote and achievable through the web interface when the theme is active. No special environmental conditions or elevated privileges are required beyond normal site access.

Affected Systems

The vulnerability affects the SmartFix theme developed by linethemes. All published versions before 1.2.4 are vulnerable; versions 1.2.4 and later are considered patched. No additional sub‑version details are provided in the advisory.

Risk and Exploitability

The CVSS score of 5.4 classifies the issue as moderate. EPSS below 1% indicates a low probability of exploitation, and the vulnerability is not present in CISA's KEV catalog. It is likely exploitable remotely via the website's interface when the theme is installed. Attackers could trigger the flaw by accessing or manipulating URLs or parameters that are protected by the theme's access control logic. The lack of required user credentials implies that unauthenticated users could leverage the flaw.

Generated by OpenCVE AI on March 19, 2026 at 14:53 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the vendor patch by upgrading the SmartFix theme to version 1.2.4 or newer.
  • Verify that your WordPress installation is running the patched theme.
  • If an upgrade is not possible, disable or delete the SmartFix theme to prevent further exploitation.
  • Periodically review your WordPress security settings and ensure that role‑based access controls are correctly configured.
  • Monitor site logs for anomalous activity or attempts to access administrative pages that trigger the vulnerability.

Generated by OpenCVE AI on March 19, 2026 at 14:53 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 16 Mar 2026 10:15:00 +0000

Type Values Removed Values Added
First Time appeared Linethemes
Linethemes smartfix
Wordpress
Wordpress wordpress
Vendors & Products Linethemes
Linethemes smartfix
Wordpress
Wordpress wordpress

Fri, 13 Mar 2026 19:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 13 Mar 2026 12:00:00 +0000

Type Values Removed Values Added
Description Missing Authorization vulnerability in linethemes SmartFix smartfix allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects SmartFix: from n/a through < 1.2.4.
Title WordPress SmartFix theme < 1.2.4 - Broken Access Control vulnerability
Weaknesses CWE-862
References

Subscriptions

Linethemes Smartfix
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-01T14:16:07.687Z

Reserved: 2026-03-12T11:11:09.667Z

Link: CVE-2026-32391

cve-icon Vulnrichment

Updated: 2026-03-13T18:55:42.622Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-03-13T19:54:54.547

Modified: 2026-03-16T14:53:46.157

Link: CVE-2026-32391

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-03-23T12:04:09Z

Weaknesses