Description
Missing Authorization vulnerability in vowelweb VW Portfolio vw-portfolio allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects VW Portfolio: from n/a through <= 1.3.3.
Published: 2026-03-13
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Broken Access Control
Action: Upgrade Immediately
AI Analysis

Impact

The vulnerability is a missing authorization flaw in the vowelweb VW Portfolio WordPress theme that allows attackers to exploit incorrectly configured access control security levels. This broken access control can let an attacker perform unauthorized actions such as editing, deleting, or viewing protected content, thereby compromising the integrity and confidentiality of the site’s data. The weakness is identified as CWE-862, indicating failure to restrict access to privileged operations.

Affected Systems

Vowelweb VW Portfolio theme versions up to and including 1.3.3 are vulnerable. The vulnerability range is described as "from n/a through <= 1.3.3," meaning that any deployment of the theme with a version number 1.3.3 or earlier is affected. No specific sub-versions are listed, so all releases within this range should be treated as susceptible.

Risk and Exploitability

The CVSS score of 5.3 suggests moderate severity, while the EPSS score of less than 1% indicates a low likelihood of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog, further supporting its current low exploitation probability. Attackers would likely exploit the flaw remotely by sending crafted HTTP requests to the theme’s endpoints, bypassing normal WordPress permission checks. This inference is based on the nature of the described missing authorization flaw in a WordPress theme, a context that typically allows remote access when misconfigured. No additional exploitation conditions are specified in the dossier.

Generated by OpenCVE AI on March 19, 2026 at 15:13 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the VW Portfolio theme to a version newer than 1.3.3 as soon as possible.
  • If an immediate upgrade is infeasible, disable or remove the theme until a patched version is available.
  • After a patch or removal, verify that all hidden or administrative endpoints are properly protected by WordPress role checks.
  • Monitor site logs for anomalous activity that may indicate exploitation of the access control flaw.

Generated by OpenCVE AI on March 19, 2026 at 15:13 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 03 Apr 2026 07:45:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 16 Mar 2026 10:15:00 +0000

Type Values Removed Values Added
First Time appeared Vowelweb
Vowelweb vw Portfolio
Wordpress
Wordpress wordpress
Vendors & Products Vowelweb
Vowelweb vw Portfolio
Wordpress
Wordpress wordpress

Fri, 13 Mar 2026 20:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N'}


Fri, 13 Mar 2026 12:00:00 +0000

Type Values Removed Values Added
Description Missing Authorization vulnerability in vowelweb VW Portfolio vw-portfolio allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects VW Portfolio: from n/a through <= 1.3.3.
Title WordPress VW Portfolio theme <= 1.3.3 - Broken Access Control vulnerability
Weaknesses CWE-862
References

Subscriptions

Vowelweb Vw Portfolio
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-01T14:16:16.754Z

Reserved: 2026-03-12T11:11:30.948Z

Link: CVE-2026-32437

cve-icon Vulnrichment

Updated: 2026-03-13T18:46:35.610Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-03-13T19:55:03.803

Modified: 2026-03-16T14:53:46.157

Link: CVE-2026-32437

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-03-23T12:03:27Z

Weaknesses