Description
Missing Authorization vulnerability in themebeez Fascinate fascinate allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Fascinate: from n/a through <= 1.1.5.
Published: 2026-07-13
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a missing authorization flaw that allows attackers to bypass the access control mechanisms of the WordPress Fascinate theme. The flaw arises from incorrectly configured security levels, which lets an unauthorized user gain access to restricted administrative functions or content. This is classified as a CWE-862 authorization error and can lead to unauthorized content modification or escalation of privileges within the site.

Affected Systems

Themebeez Fascinate theme for WordPress, specifically any installation of version 1.1.5 or earlier. The issue is present across all versions from the earliest available release up to and including 1.1.5.

Risk and Exploitability

The CVSS score of 5.3 indicates a medium severity impact. The EPSS score of less than 1% suggests that the probability of exploitation is low and the vulnerability is uncommon in the wild. It is not listed in CISA’s KEV catalogue. The lack of detailed exploitation steps in the description means the attack vector is inferred to involve UI or URL manipulation to reach the vulnerable administrative pages, potentially exploiting incorrectly set role permissions.

Generated by OpenCVE AI on August 1, 2026 at 10:30 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Fascinate theme to the latest version released after 1.1.5.
  • If an upgrade is not immediately possible, restrict web access to the theme’s administrative URLs using server‑side access controls (e.g., .htaccess or Nginx rules) to limit exposure to trusted roles.
  • Apply a role‑based access control plugin or modify the theme’s code to enforce strict authorization checks before rendering or processing any privileged requests.

Generated by OpenCVE AI on August 1, 2026 at 10:30 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 13 Jul 2026 15:00:00 +0000

Type Values Removed Values Added
First Time appeared Themebeez
Themebeez fascinate
Wordpress
Wordpress wordpress
Vendors & Products Themebeez
Themebeez fascinate
Wordpress
Wordpress wordpress

Mon, 13 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 13 Jul 2026 10:00:00 +0000

Type Values Removed Values Added
Description Missing Authorization vulnerability in themebeez Fascinate fascinate allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Fascinate: from n/a through <= 1.1.5.
Title WordPress Fascinate theme <= 1.1.5 - Broken Access Control vulnerability
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N'}


Subscriptions

Themebeez Fascinate
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-07-13T13:32:54.093Z

Reserved: 2026-06-25T08:04:53.458Z

Link: CVE-2026-57779

cve-icon Vulnrichment

Updated: 2026-07-13T13:32:50.382Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-01T10:45:03Z

Weaknesses