CVE-2026-102383: WordPress Lookzy plugin <= 1.1.14 - Broken Access Control vulnerability
Missing Authorization vulnerability in VillaTheme Lookzy woo-lookbook allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Lookzy: from n/a through 1.1.14.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Lookzy pluginto a version that resolves this vulnerability.Fixed in 1.1.15
Event History
Frequently Asked Questions
Who can exploit this issue?
The CVSS vector indicates that exploitation is network-accessible, requires no privileges, and does not require user interaction. This means an unauthenticated remote attacker may be able to exploit the affected access-control weakness.
Which installations are affected?
Lookzy versions through 1.1.14 are affected. The available information does not state whether any particular WordPress or plugin configuration is required.
What is the potential impact?
The reported impact includes low integrity and availability effects, while confidentiality impact is listed as none. The issue is rated medium severity with a CVSS score of 6.5.