Description
Unauthenticated Broken Access Control in Civi <= 2.2.4 versions.
Published: 2026-07-23
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Civi theme for WordPress (uxper) suffers from an unauthenticated broken access control flaw (CWE‑862). The flaw allows a visitor to reach administrative or privileged functions that should require authentication, potentially enabling the creation of content or modification of settings that are normally reserved for administrators. Unchecked access leads to unauthorized manipulation and exposure of sensitive configuration.

Affected Systems

The vulnerability affects the Civi theme version 2.2.4 and all earlier releases. The vendor uxper has not specified a fixed version, so any release newer than 2.2.4 should be verified for a patch. WordPress plugins or themes that have not been updated beyond this point remain vulnerable.

Risk and Exploitability

The CVSS score of 5.3 indicates a moderate impact, whereas the EPSS score of < 1% reflects a low probability of exploitation. The issue is not in the CISA KEV catalog, implying no widespread known exploits. Attackers likely target unauthenticated HTTP endpoints that incorrectly bypass authentication checks, which is inferred from the description of broken access control.

Generated by OpenCVE AI on August 3, 2026 at 22:04 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Civi theme to a version newer than 2.2.4 once the vendor releases a fix.
  • If an upgrade is not immediately feasible, block unauthenticated access to the theme’s administrative endpoints using a security plugin or .htaccess rules.
  • Regularly review WordPress user roles and enforce the principle of least privilege to limit the damage if the flaw is exploited.
  • Continuously monitor web server logs for suspicious access attempts to the Civi theme’s admin functionality.

Generated by OpenCVE AI on August 3, 2026 at 22:04 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 23 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 23 Jul 2026 14:15:00 +0000

Type Values Removed Values Added
First Time appeared Uxper
Uxper civi
Wordpress
Wordpress wordpress
Vendors & Products Uxper
Uxper civi
Wordpress
Wordpress wordpress

Thu, 23 Jul 2026 11:45:00 +0000

Type Values Removed Values Added
Description Unauthenticated Broken Access Control in Civi <= 2.2.4 versions.
Title WordPress Civi theme <= 2.2.4 - Broken Access Control vulnerability
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-07-23T13:40:00.430Z

Reserved: 2026-07-22T08:53:30.834Z

Link: CVE-2026-65476

cve-icon Vulnrichment

Updated: 2026-07-23T13:39:53.156Z

cve-icon NVD

Status : Deferred

Published: 2026-07-23T12:18:40.470

Modified: 2026-07-23T14:17:51.020

Link: CVE-2026-65476

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T22:15:04Z

Weaknesses