CVE-2025-53986: WordPress Hestia theme <= 3.2.10 - Broken Access Control Vulnerability
Missing Authorization vulnerability in ThemeIsle Hestia allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Hestia: from n/a through 3.2.10.
Other sources
Missing Authorization vulnerability in themeisle Hestia hestia allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Hestia: from n/a through <= 3.2.10.
— MITRE
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-53986?
CVE-2025-53986 is classified as a missing authorization vulnerability with potential for unauthorized access.
How do I fix CVE-2025-53986?
To fix CVE-2025-53986, update the ThemeIsle Hestia to version 3.2.11 or later.
What software versions are affected by CVE-2025-53986?
CVE-2025-53986 affects ThemeIsle Hestia versions from n/a through 3.2.10.
What type of vulnerability is CVE-2025-53986?
CVE-2025-53986 is a missing authorization vulnerability that allows unauthorized functionality access.
How can CVE-2025-53986 impact my website?
CVE-2025-53986 can compromise your website's security by allowing users to access restricted functions without proper authorization.