CVE-2025-52804
7.5uxper · Nuss
A missing authorization vulnerability in the uxper Nuss theme allows unauthenticated attackers to access and manipulate functionality that is not properly constrained by access control lists.
Executive summary
The uxper Nuss theme is vulnerable to a missing authorization flaw that permits unauthorized access to restricted functionality, posing a significant risk to site integrity.
Vulnerability
This vulnerability is a Missing Authorization flaw (CWE-862) within the Nuss theme. It allows an unauthenticated attacker to interact with restricted functions because the software fails to perform proper capability checks or verify user permissions before executing sensitive operations.
Business impact
The ability for unauthenticated users to bypass access controls can lead to unauthorized modification of site data or settings, potentially resulting in site defacement or the compromise of administrative workflows. Given the CVSS score of 7.5, this vulnerability represents a high risk to business operations, as it is remotely exploitable without requiring any user interaction or prior authentication.
Remediation
Immediate Action: Review the official uxper vendor portal for the latest theme release and update to a version beyond 1.3.7.1 immediately.
Proactive Monitoring: Monitor server access logs for anomalous requests targeting theme-specific endpoints or unauthorized attempts to perform administrative actions.
Compensating Controls: Deploy a Web Application Firewall (WAF) with rules configured to block unauthorized requests to theme-specific files and sensitive administrative paths.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
The severity of this vulnerability necessitates immediate attention from security administrators managing WordPress environments utilizing the Nuss theme. Because the flaw allows for unauthenticated access to restricted functions, it is critical to verify the current theme version and apply the vendor patch as soon as it is released. Until an update is applied, ensure that access to the WordPress dashboard and related backend directories is strictly restricted to authorized personnel.
More uxper CVEs
Sources
Originally found and disclosed by Aiden | Patchstack Bug Bounty Program, per the CVE Program record.