CVE-2026-40809: WordPress Metro Magazine theme <= 1.4.1 - Broken Access Control vulnerability
Published Jun 16, 2026
·Updated
Missing Authorization vulnerability in Rara Themes Metro Magazine allows Exploiting Incorrectly Configured Access Control Security Levels.
This issue affects Metro Magazine: from n/a through 1.4.1.
Affected Software
1 affected component
Rara Themes Metro Magazine<=1.4.1
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Metro Magazine themeto a version that resolves this vulnerability.Fixed in 1.4.2
Event History
Jun 16, 2026
CVE Published
via MITRE·09:05 AM
Data Sourced
via MITRE·09:05 AM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·10:16 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-40809?
The severity of CVE-2026-40809 is rated medium with a score of 6.5.
2
How do I fix CVE-2026-40809?
To fix CVE-2026-40809, update the Rara Themes Metro Magazine theme to version 1.4.2 or later.
3
What is the impact of CVE-2026-40809?
CVE-2026-40809 allows for broken access control that may enable unauthorized access to certain functionalities.
4
Which versions of Metro Magazine are affected by CVE-2026-40809?
CVE-2026-40809 affects Metro Magazine theme versions from n/a up to 1.4.1.
5
Who is the vendor for CVE-2026-40809?
The vendor for CVE-2026-40809 is Rara Themes.