Description
Subscriber Broken Access Control in Martfury - WooCommerce Marketplace WordPress Theme <= 3.2.8 versions.
Published: 2026-07-02
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a broken access control flaw that affects all releases up to and including version 3.2.8 of the Martfury – WooCommerce Marketplace WordPress Theme. It allows users with the Subscriber role to bypass intended restrictions in the theme’s functionality, potentially allowing them to access or manipulate elements that should otherwise be protected. The issue is classified as CWE‑862, an authorization weakness; based on the description, it is inferred that the vulnerability could expose administrative capabilities to a lower‑privileged user.

Affected Systems

The affected products are the Martfury – WooCommerce Marketplace WordPress Theme developed by Drfuri; any installations using version 3.2.8 or earlier are susceptible. Versions newer than 3.2.8 are not impacted.

Risk and Exploitability

The CVSS score of 4.3 indicates a low to moderate severity, and the EPSS score of less than 1% suggests a very low probability of exploitation at present. The vulnerability is not listed in the CISA KEV catalog. Attackers would need to possess a Subscriber account and exploit the theme’s oversight of access controls; based on the nature of broken access control, the likely attack vector may involve sending crafted requests or interacting with exposed theme interfaces. Because the exact privileges gained are not detailed in the data, the precise scope of damage remains uncertain, but the risk of unintended access to theme settings is evident.

Generated by OpenCVE AI on August 1, 2026 at 21:34 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Martfury theme to any version newer than 3.2.8
  • Restrict the Subscriber role from accessing the theme’s admin settings by adjusting role capabilities or using a role‑management plugin
  • If an immediate upgrade is not possible, block access to the theme’s configuration endpoints through custom code or .htaccess rules
  • Monitor site logs for suspicious activity involving the theme settings and update maintenance procedures accordingly

Generated by OpenCVE AI on August 1, 2026 at 21:34 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 06 Jul 2026 23:15:00 +0000

Type Values Removed Values Added
First Time appeared Drfuri
Drfuri martfury - Woocommerce Marketplace Wordpress Theme
Wordpress
Wordpress wordpress
Vendors & Products Drfuri
Drfuri martfury - Woocommerce Marketplace Wordpress Theme
Wordpress
Wordpress wordpress

Sat, 04 Jul 2026 02:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 02 Jul 2026 11:30:00 +0000

Type Values Removed Values Added
Description Subscriber Broken Access Control in Martfury - WooCommerce Marketplace WordPress Theme <= 3.2.8 versions.
Title WordPress Martfury - WooCommerce Marketplace WordPress theme theme <= 3.2.8 - Broken Access Control vulnerability
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'}


Subscriptions

Drfuri Martfury - Woocommerce Marketplace Wordpress Theme
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-07-02T12:41:48.874Z

Reserved: 2026-06-25T08:03:42.567Z

Link: CVE-2026-57685

cve-icon Vulnrichment

Updated: 2026-07-02T12:41:45.815Z

cve-icon NVD

Status : Deferred

Published: 2026-07-02T12:17:39.327

Modified: 2026-07-02T13:58:23.330

Link: CVE-2026-57685

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-01T21:45:05Z

Weaknesses