Description
Missing Authorization vulnerability in themehunk Open Shop open-shop allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Open Shop: from n/a through <= 1.7.1.
Published: 2026-07-13
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Open Shop WordPress theme contains a missing authorization flaw that allows attackers to exploit incorrectly configured access control levels. As a result, a user who can invoke the vulnerable code paths may gain unauthorized read, modify, or delete capabilities over the site’s content. Based on the description, the vulnerability is a classic broken access control weakness as defined by CWE-862, and the likely attack requires the attacker to interact with the site’s theme layer, though the exact user privilege needed is not specified in the data.

Affected Systems

WordPress sites that have installed the Open Shop theme version 1.7.1 or earlier are affected. The theme, provided by themehunk, is vulnerable in all releases from the initial version up through 1.7.1, so any site using any of those releases should review its theme configuration and version.

Risk and Exploitability

The CVSS score of 7.1 classifies the issue as high severity, while the EPSS score of <1% indicates a very low probability of exploitation at present. The vulnerability is not listed in CISA’s KEV catalog. Exploitation would involve targeting a WordPress installation that has the Open Shop theme active and relying on the theme’s flawed access‑control implementation; no publicly documented exploit exists, but the flaw could enable privilege escalation if an attacker can trigger the vulnerable code.

Generated by OpenCVE AI on July 31, 2026 at 11:57 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Open Shop theme to any version newer than 1.7.1.
  • If an update is not available, deactivate or replace the theme with a vetted alternative.
  • Restrict administrator and editor roles so that only trusted users receive theme‑specific administrative privileges.
  • Review and harden role permissions to eliminate over‑privileged accounts.
  • Monitor site logs for unauthorized activity and review error logs for anomalies.

Generated by OpenCVE AI on July 31, 2026 at 11:57 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 13 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 13 Jul 2026 15:00:00 +0000

Type Values Removed Values Added
First Time appeared Themehunk
Themehunk open Shop
Wordpress
Wordpress wordpress
Vendors & Products Themehunk
Themehunk open Shop
Wordpress
Wordpress wordpress

Mon, 13 Jul 2026 10:00:00 +0000

Type Values Removed Values Added
Description Missing Authorization vulnerability in themehunk Open Shop open-shop allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Open Shop: from n/a through <= 1.7.1.
Title WordPress Open Shop theme <= 1.7.1 - Broken Access Control vulnerability
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H'}


Subscriptions

Themehunk Open Shop
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-07-13T14:39:11.681Z

Reserved: 2026-06-24T12:46:27.804Z

Link: CVE-2026-57405

cve-icon Vulnrichment

Updated: 2026-07-13T13:54:48.046Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T12:00:05Z

Weaknesses