CVE-2026-105883: WordPress Th Shop Mania theme <= 1.9.1 - Broken Access Control vulnerability
Missing Authorization vulnerability in ThemeHunk Th Shop Mania th-shop-mania allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Th Shop Mania: from n/a through 1.9.1.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
wordpress/th-shop-maniato a version that resolves this vulnerability.Fixed in 1.9.2
Event History
Frequently Asked Questions
Who can exploit this issue?
The vulnerability requires an attacker to have low-level privileges. It can be exploited remotely and does not require user interaction.
What impact could successful exploitation have?
Successful exploitation may allow unauthorized modification of data and could cause a high availability impact. The provided severity vector does not indicate a confidentiality impact.
Which versions are affected?
Th Shop Mania versions through 1.9.1 are affected. The available information does not identify a fixed version.