CVE-2025-52803
7.5uxper · Sala
A missing authorization vulnerability in the uxper Sala theme allows unauthenticated attackers to access restricted functionality due to improperly constrained access control lists.
Executive summary
The uxper Sala theme contains a critical missing authorization vulnerability that permits unauthorized access to restricted functions, posing a significant risk to site integrity.
Vulnerability
This is a missing authorization flaw, categorized as CWE-862, where the application fails to perform adequate capability checks. The vulnerability allows an unauthenticated attacker to interact with functions that should be restricted to authorized users.
Business impact
The ability to bypass access controls can lead to unauthorized modification of site settings or data, potentially compromising the integrity of the WordPress environment. With a CVSS score of 7.5, this high-severity flaw represents a significant risk, as it allows attackers to perform actions without authentication, which could lead to complete administrative takeover of the affected theme settings.
Remediation
Immediate Action: Review the official Patchstack advisory for the Sala theme to determine if a fix has been released; if no patch is available, consider switching to an alternative theme until the vendor provides a secure update.
Proactive Monitoring: Monitor server access logs for anomalous requests to administrative endpoints or unexpected changes to theme configurations.
Compensating Controls: Deploy a Web Application Firewall (WAF) with rules configured to block unauthorized access attempts to theme-specific functions and administrative paths.
Exploitation status
Public Exploit Available: No — there is no confirmed public exploit available.
Analyst recommendation
Given the high CVSS score and the potential for unauthenticated access, administrators must prioritize addressing this vulnerability. If an update is not currently available from uxper, disable the affected functionality or the theme itself to prevent potential exploitation until a vendor-supplied patch is successfully applied.
More uxper CVEs
Sources
Originally found and disclosed by Thái An (Patchstack Alliance), per the CVE Program record.