VYPR
Medium severity4.3NVD Advisory· Published Jun 11, 2026· Updated Jun 11, 2026

CVE-2023-32959

CVE-2023-32959

Description

Missing authorization in MetroStore WordPress theme up to 1.3.2 allows unauthenticated attackers to perform privileged actions.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Missing authorization in MetroStore WordPress theme up to 1.3.2 allows unauthenticated attackers to perform privileged actions.

Vulnerability

The MetroStore WordPress theme versions from n/a through 1.3.2 contain a missing authorization vulnerability [1]. The theme fails to properly enforce access control checks on certain functions, allowing unauthenticated or low-privileged users to access administrative capabilities.

Exploitation

An attacker with no prior authentication or with a low-privileged account can exploit this broken access control by sending crafted requests to the vulnerable endpoints [1]. No special network position or user interaction is required; the attack can be performed remotely.

Impact

Successful exploitation enables an unprivileged attacker to execute actions that should be restricted to higher-privileged users, such as modifying theme settings or other administrative operations [1]. This can lead to unauthorized changes to the website's configuration.

Mitigation

The theme has not received updates for over a year and is likely abandoned; no official patch is available [1]. The recommended mitigation is to remove and replace the theme with an actively maintained alternative. Deactivating the theme does not eliminate the security risk. Patchstack offers a mitigation rule to block attacks until a permanent fix can be applied [1].

AI Insight generated on Jun 11, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

No source-code context for this CVE — mechanics is only generated when we can read the actual fix diff. Without that, the four sections (root cause, attack vector, affected code, fix) would be speculation rather than analysis.

References

1

News mentions

0

No linked articles in our index yet.