CVE-2025-53999: WordPress Altair theme <= 5.2.2 - Broken Access Control vulnerability
Published Aug 20, 2026
·Updated
Unauthenticated Broken Access Control in Altair <= 5.2.2 versions.
Affected Software
1 affected component
WordPress Altair theme<=5.2.2
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Altair themeto a version that resolves this vulnerability.Fixed in 5.2.2
Event History
Aug 20, 2026
CVE Published
via MITRE·12:06 PM
Data Sourced
via MITRE·12:06 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Who can exploit this issue?
The vulnerability is unauthenticated, so an attacker does not need a WordPress account or prior privileges. It is remotely reachable over the network and requires no user interaction.
2
What security impact is indicated?
The reported impact includes integrity and availability effects, while confidentiality impact is listed as none. The CVSS vector indicates the scope is unchanged.
3
Which Altair versions are affected?
Altair theme versions up to and including 5.2.2 are identified as affected.