Description
Missing Authorization vulnerability in Brainstorm Force Starter Templates astra-sites allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Starter Templates: from n/a through 4.7.7.
Published: 2026-10-05
Score: 5.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized Access
Action: Update Plugin
AI Analysis

Impact

Missing authorization in the WordPress Starter Templates plugin causes authenticated users to gain access to administrative functions that should be restricted. The flaw is an improper capability check, classified as CWE‑862. An attacker can modify or delete template settings, potentially compromising site content and configuration.

Affected Systems

The affected product is the WordPress Starter Templates plugin distributed by Brainstorm Force. Installations of version 4.7.7 or earlier are vulnerable. Starting with version 4.7.8 the issue has been fixed.

Risk and Exploitability

The CVSS score of 5.4 indicates a moderate severity. EPSS is not available and the vulnerability is not listed in CISA KEV, so the likelihood of exploitation remains undetermined. The description suggests missing authorization for plugin settings, so it is inferred that an authenticated user with normal login credentials could exploit the flaw to modify template settings. No evidence of remote code execution or denial of service is indicated.

Generated by OpenCVE AI on October 5, 2026 at 11:05 UTC.

Remediation

Vendor Solution

Update the WordPress Starter Templates plugin to the latest available version (at least 4.7.8).


OpenCVE Recommended Actions

  • Apply the latest patch by updating the WordPress Starter Templates plugin to version 4.7.8 or later.
  • If an upgrade is not immediately possible, restrict plugin access by disabling the plugin or limiting its administration pages to administrators only.
  • Review site activity logs for suspicious changes to template settings after an upgrade.

Generated by OpenCVE AI on October 5, 2026 at 11:05 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 05 Oct 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 05 Oct 2026 09:15:00 +0000

Type Values Removed Values Added
Description Missing Authorization vulnerability in Brainstorm Force Starter Templates astra-sites allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Starter Templates: from n/a through 4.7.7.
Title WordPress Starter Templates plugin <= 4.7.7 - Broken Access Control vulnerability
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-10-05T15:28:52.287Z

Reserved: 2026-04-07T10:58:29.177Z

Link: CVE-2026-39721

cve-icon Vulnrichment

Updated: 2026-10-05T14:46:50.708Z

cve-icon NVD

Status : Received

Published: 2026-10-05T09:17:13.227

Modified: 2026-10-05T16:17:13.373

Link: CVE-2026-39721

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-05T11:15:07Z

Weaknesses