Description
Missing Authorization vulnerability in vowelweb VW Food Corner vw-food-corner allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects VW Food Corner: from n/a through <= 1.1.0.
Published: 2026-07-13
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability stems from a missing authorization Corner WordPress theme. This broken access control allows an attacker to access or modify theme configurations and data that should be restricted to privileged users, potentially exposing sensitive information or altering site appearance. The weakness is classified as CWE‑862, indicating an authorization failure that could compromise data integrity or confidentiality.

Affected Systems

All installations of the vowelweb VW Food Corner theme with a version of 1.1.0 or earlier are susceptible. The affected product is the WordPress theme "VW Food Corner" by vowelweb; users should check the theme version and apply any available update that addresses the authorization issue.

Risk and Exploitability

The CVSS score of 5.3 indicates a moderate impact. The EPSS score is below 1%, implying a low probability that this flaw is currently exploited in the wild, and the vulnerability is not listed in the CISA KEV catalog. Thus, while the risk is moderate, the likelihood of exploitation is low. Based on the description, it is inferred that the attack vector involves an attacker already having some level of access to the WordPress site, as the flaw pertains to theme configuration pages site with the vulnerable theme, they can potentially read or alter theme data without proper privilege checks.

Generated by OpenCVE AI on August 1, 2026 at 10:31 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest update for the VW Food Corner theme that fixes the authorization flaw.
  • If an update is not by reviewing role capabilities and removing any unnecessary permissions.
  • Validate that only intended administrators can access and modify theme settings, and perform regular audits of role assignments and theme configuration to ensure no unauthorized changes occur.

Generated by OpenCVE AI on August 1, 2026 at 10:31 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 13 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 13 Jul 2026 15:00:00 +0000

Type Values Removed Values Added
First Time appeared Vowelweb
Vowelweb vw Food Corner
Wordpress
Wordpress wordpress
Vendors & Products Vowelweb
Vowelweb vw Food Corner
Wordpress
Wordpress wordpress

Mon, 13 Jul 2026 10:00:00 +0000

Type Values Removed Values Added
Description Missing Authorization vulnerability in vowelweb VW Food Corner vw-food-corner allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects VW Food Corner: from n/a through <= 1.1.0.
Title WordPress VW Food Corner theme <= 1.1.0 - Broken Access Control vulnerability
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L'}


Subscriptions

Vowelweb Vw Food Corner
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-07-13T13:53:45.683Z

Reserved: 2026-06-25T08:04:47.959Z

Link: CVE-2026-57774

cve-icon Vulnrichment

Updated: 2026-07-13T13:53:42.680Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-01T10:45:03Z

Weaknesses