VYPR
Medium severity5.3NVD Advisory· Published Mar 13, 2026· Updated Apr 22, 2026

CVE-2026-32487

CVE-2026-32487

Description

Missing Authorization vulnerability in raratheme Lawyer Landing Page lawyer-landing-page allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Lawyer Landing Page: from n/a through <= 1.2.7.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Lawyer Landing Page theme ≤1.2.7 has a missing authorization vulnerability allowing unauthenticated access to higher-privileged actions.

Vulnerability

Overview

The Lawyer Landing Page theme for WordPress, versions up to and including 1.2.7, contains a missing authorization vulnerability. This broken access control flaw stems from an incorrect configuration of access control security levels, meaning theme functions that should require higher privileges do not properly check for authentication or authorization tokens [1]. As a result, the theme fails to enforce privilege separation for certain actions.

Exploitation

This vulnerability is categorized as a broken access control issue where unprivileged users — potentially including unauthenticated visitors — can execute actions that are normally reserved for higher-privileged roles such as administrators. The attack surface is broad because no special prerequisites are needed beyond a publicly accessible WordPress site running the affected theme version [1]. Attackers can exploit this in mass campaigns, targeting thousands of sites regardless of size or popularity.

Impact

Successful exploitation enables an attacker to perform unauthorized operations within the WordPress installation, possibly leading to site defacement, data exposure, or further privilege escalation. The vendor advisory notes that such vulnerabilities are frequently used in mass-exploit campaigns due to the low barrier to exploitation [1].

Mitigation

Users should immediately update the theme to a patched version if available. For those unable to update, contacting the hosting provider or a web developer is recommended. The vulnerability affects all versions from n/a through 1.2.7, so any site running these versions is at risk [1].

AI Insight generated on May 18, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.