Description
Contributor Broken Access Control in Style Kits <= 2.6.5 versions.
Published: 2026-07-23
Score: 6.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability is a broken access control flaw in the AnalogWP Style Kits WordPress plugin versions up to and including 2.6.5. An attacker who obtains a contributor or higher privilege can create, modify, or delete style kits that should be restricted. The flaw, identified as CWE‑862, allows an attacker to alter the visual presentation of a WordPress site, resulting in unauthorized changes to the site’s appearance.

Affected Systems

The affected product is the AnalogWP Style Kits WordPress plugin, specifically all editions with versions 2.6.5 and earlier. No other components or plugins are listed as impacted.

Risk and Exploitability

The CVSS score of 6.3 denotes medium severity, and the EPSS score of < 1 % indicates a very low likelihood of exploitation at present. The issue is not listed in the CISA KEV catalog. The attacker must be authenticated with at least contributor-level rights, and the most likely attack vector is through the plugin’s authenticated web interface. Based on the description, it is inferred that the exploitation path involves using the plugin’s settings or administration pages to manage style kits without adequate permission checks.

Generated by OpenCVE AI on August 4, 2026 at 15:24 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the AnalogWP Style Kits plugin to a version newer than 2.6.5
  • Review WordPress user role permissions and ensure contributors cannot edit style kits; remove any over‑privileged capabilities
  • If the plugin is not essential, disable or uninstall it completely

Generated by OpenCVE AI on August 4, 2026 at 15:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 23 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 23 Jul 2026 15:15:00 +0000

Type Values Removed Values Added
First Time appeared Analogwp
Analogwp style Kits
Wordpress
Wordpress wordpress
Vendors & Products Analogwp
Analogwp style Kits
Wordpress
Wordpress wordpress

Thu, 23 Jul 2026 11:45:00 +0000

Type Values Removed Values Added
Description Contributor Broken Access Control in Style Kits <= 2.6.5 versions.
Title WordPress Style Kits plugin <= 2.6.5 - Broken Access Control vulnerability
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L'}


Subscriptions

Analogwp Style Kits
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-07-23T14:42:47.774Z

Reserved: 2026-07-22T08:53:35.326Z

Link: CVE-2026-65484

cve-icon Vulnrichment

Updated: 2026-07-23T14:42:42.430Z

cve-icon NVD

Status : Deferred

Published: 2026-07-23T12:18:41.470

Modified: 2026-07-23T15:18:03.603

Link: CVE-2026-65484

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T15:30:06Z

Weaknesses