CVE-2026-66588
Received Received - Intake

Unauthenticated Broken Access Control in The7 Theme

Vulnerability report for CVE-2026-66588, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-06

Last updated on: 2026-10-06

Assigner: Patchstack

Description

Unauthenticated Broken Access Control in The7 <= 14.2.2 versions.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-06
Last Modified
2026-10-06
Generated
2026-10-06
AI Q&A
2026-10-06
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
Dream-Theme The7 n/a

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-862 The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is an unauthenticated broken access control vulnerability in The7 WordPress theme versions 14.2.2 and below. It allows unauthenticated users to access restricted pages or perform unauthorized actions without proper permissions.

Detection Guidance

To detect this vulnerability, check if your The7 theme version is 14.2.2 or below. You can do this by logging into your WordPress dashboard, navigating to Appearance > Themes, and verifying the version number. If you have access to the server, you can also check the theme's version via the filesystem or database.

Impact Analysis

Unauthorized users could access sensitive data or perform restricted actions. While severity is low, exploitation may lead to data exposure. No official patch exists, so users should update immediately or contact their hosting provider.

Mitigation Strategies

Immediately update the The7 theme to the latest version if available. If no patch exists, contact your hosting provider or a developer for assistance. Consider temporarily disabling the theme if an update is not possible, but this may affect site functionality.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-66588. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart