Description
Subscriber Broken Access Control in Werkstatt <= 4.7.2 versions.
Published: 2026-07-02
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The defect is a broken access control (CWE-862) in the WordPress Werkstatt theme that allows certain authenticated users to perform actions that should be restricted to higher‑privileged roles. The description notes that subscribers are affected, implying that a logged‑in subscriber can access protected theme functions. This could be leveraged to modify theme settings, potentially compromising site appearance or integrity and, if the theme exposes additional configuration options, enabling further compromise of the WordPress environment.

Affected Systems

Non‑vulnerable versions are not identified in the CVE data, but the text specifies that all releases of the Fuelthemes Werkstatt theme up to and including version 4.7.2 are affected. The flaw manifests on WordPress installations that have the theme active. No other WordPress components are mentioned as affected.

Risk and Exploitability

The CVSS score of 4.3 indicates a moderate severity. An EPSS score of less than 1% and the absence from the CISA KEV catalogue suggest that exploitation is not widespread or actively leveraged. The vulnerability requires that the attacker be authenticated as a subscriber or otherwise gain an account with publishing privileges, indicating a local account attack vector rather than pure remote exploitation. Consequently, users should prioritize updating the theme or mitigating access for subscriber roles.

Generated by OpenCVE AI on August 1, 2026 at 21:33 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the Werkstatt theme to the latest release that resolves the broken access‑control flaw.
  • If the theme cannot be updated immediately, disable the theme or switch to a non‑vulnerable theme to prevent the flaw from being exploitable.
  • Limit the capabilities of the subscriber role so that they cannot access or modify theme settings, using a role‑management plugin or custom code.
  • Check the Fuelthemes plugin repository or security bulletin for any additional remediation guidance.

Generated by OpenCVE AI on August 1, 2026 at 21:33 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 06 Jul 2026 23:15:00 +0000

Type Values Removed Values Added
First Time appeared Fuelthemes
Fuelthemes werkstatt
Wordpress
Wordpress wordpress
Vendors & Products Fuelthemes
Fuelthemes werkstatt
Wordpress
Wordpress wordpress

Thu, 02 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 02 Jul 2026 11:30:00 +0000

Type Values Removed Values Added
Description Subscriber Broken Access Control in Werkstatt <= 4.7.2 versions.
Title WordPress Werkstatt theme <= 4.7.2 - Broken Access Control vulnerability
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}


Subscriptions

Fuelthemes Werkstatt
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-07-02T15:52:52.711Z

Reserved: 2026-06-25T08:03:50.157Z

Link: CVE-2026-57689

cve-icon Vulnrichment

Updated: 2026-07-02T13:33:25.468Z

cve-icon NVD

Status : Deferred

Published: 2026-07-02T12:17:39.810

Modified: 2026-07-02T16:16:34.913

Link: CVE-2026-57689

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-01T21:45:05Z

Weaknesses