CVE-2026-103072: WordPress VillaTheme Core plugin <= 1.0.5 - Broken Access Control vulnerability
Published Oct 8, 2026
·Updated
Missing Authorization vulnerability in VillaTheme VillaTheme Core villatheme-core allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects VillaTheme Core: from n/a through 1.0.5.
Affected Software
1 affected component
Villatheme VillaTheme Core<=1.0.5
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress VillaTheme Core pluginto a version that resolves this vulnerability.Fixed in 1.0.6
Event History
Oct 8, 2026
CVE Published
via MITRE·01:03 PM
Data Sourced
via MITRE·01:03 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·01:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Who can exploit this issue?
The CVSS vector indicates that network access is sufficient, but an attacker must have low-level privileges. No user interaction is required.
2
What is the likely impact if exploitation succeeds?
The reported impact is limited confidentiality loss. Integrity and availability impacts are not indicated by the provided CVSS vector.
3
Which versions are affected?
VillaTheme Core versions through 1.0.5 are affected. The provided data does not identify a fixed version.