Description
Missing Authorization vulnerability in vowelweb VW Wedding vw-wedding allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects VW Wedding: from n/a through <= 1.3.7.
Published: 2026-07-13
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability is a broken access control flaw in the VW Wedding WordPress theme that allows an attacker to bypass authorization checks for restricted content and administrative actions. The missing authorization creates a path for unauthenticated or low‑privilege users to read, modify, or delete theme configuration data, potentially altering site appearance, content, or compromising sensitive information. The weakness is identified as CWE‑862, highlighting improper access control enforcement.

Affected Systems

The vulnerability affects the VW Wedding theme developed by vowelweb, specifically versions 1.3.7 and earlier. Any WordPress site that has this theme installed and has not applied the update to a later, fixed version is susceptible.

Risk and Exploitability

The CVSS score of 5.3 places this issue in the medium severity range, indicating a reasonable risk level. The EPSS score of less than 1% suggests a low probability of exploitation in the wild. It is not listed in CISA’s KEV catalog. Based on the description, the likely attack vector is a web‑based request to the affected WordPress installation, where an attacker can exploit the missing authorization to gain unauthorized access to sensitive theme functions.

Generated by OpenCVE AI on August 1, 2026 at 10:31 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the VW Wedding theme to the latest version that removes the access control flaw.
  • If the theme cannot be updated immediately, disable or remove the theme from the active installation to block the vulnerable code.
  • Implement temporary access controls by restricting user roles or file permissions so that only trusted administrators can modify theme settings until a patch is applied.

Generated by OpenCVE AI on August 1, 2026 at 10:31 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 13 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 13 Jul 2026 15:00:00 +0000

Type Values Removed Values Added
First Time appeared Vowelweb
Vowelweb vw Wedding
Wordpress
Wordpress wordpress
Vendors & Products Vowelweb
Vowelweb vw Wedding
Wordpress
Wordpress wordpress

Mon, 13 Jul 2026 10:00:00 +0000

Type Values Removed Values Added
Description Missing Authorization vulnerability in vowelweb VW Wedding vw-wedding allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects VW Wedding: from n/a through <= 1.3.7.
Title WordPress VW Wedding theme <= 1.3.7 - Broken Access Control vulnerability
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L'}


Subscriptions

Vowelweb Vw Wedding
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-07-13T14:27:26.750Z

Reserved: 2026-06-25T08:04:47.960Z

Link: CVE-2026-57776

cve-icon Vulnrichment

Updated: 2026-07-13T14:27:22.614Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-01T10:45:03Z

Weaknesses