CVE-2026-66647: WordPress Homlisti theme <= 3.1.2 - Broken Access Control vulnerability
Published Aug 20, 2026
·Updated
Subscriber Broken Access Control in Homlisti <= 3.1.2 versions.
Affected Software
1 affected component
Homlisti theme<=3.1.2
Event History
Aug 20, 2026
CVE Published
via MITRE·12:07 PM
Data Sourced
via MITRE·12:07 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Who can exploit this issue?
An authenticated user with Subscriber-level access can exploit the broken access control condition. No user interaction is required, and the issue is remotely exploitable.
2
What is the security impact?
The vulnerability can affect integrity, meaning a Subscriber may be able to perform unauthorized modifications. The provided data does not indicate confidentiality or availability impact.
3
Which installations are affected?
Homlisti theme versions up to and including 3.1.2 are affected. The provided data does not identify a fixed version or any configuration prerequisites.