CVE-2026-27364: WordPress Style Kits plugin <= 2.6.5 - Broken Access Control vulnerability
Published Aug 24, 2026
·Updated
Subscriber Broken Access Control in Style Kits <= 2.6.5 versions.
Affected Software
1 affected component
WordPress Style Kits<=2.6.5
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Style Kits Pluginto a version that resolves this vulnerability.Fixed in 2.6.6
Event History
Aug 24, 2026
CVE Published
via MITRE·09:31 PM
Data Sourced
via MITRE·09:31 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·10:16 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What level of access does an attacker need to exploit this issue?
The vulnerability requires authenticated Subscriber-level access. It does not require user interaction and can be exploited over the network.
2
What is the likely impact if exploited?
Successful exploitation can result in unauthorized modification of data or settings. The available information does not indicate confidentiality or availability impact.
3
Which versions are affected?
Style Kits versions 2.6.5 and earlier are affected.