CVE-2025-52804

7.5

uxper · Nuss

A missing authorization vulnerability in the uxper Nuss theme allows unauthenticated attackers to access and manipulate functionality that is not properly constrained by access control lists.

Executive summary

The uxper Nuss theme is vulnerable to a missing authorization flaw that permits unauthorized access to restricted functionality, posing a significant risk to site integrity.

Vulnerability

This vulnerability is a Missing Authorization flaw (CWE-862) within the Nuss theme. It allows an unauthenticated attacker to interact with restricted functions because the software fails to perform proper capability checks or verify user permissions before executing sensitive operations.

Business impact

The ability for unauthenticated users to bypass access controls can lead to unauthorized modification of site data or settings, potentially resulting in site defacement or the compromise of administrative workflows. Given the CVSS score of 7.5, this vulnerability represents a high risk to business operations, as it is remotely exploitable without requiring any user interaction or prior authentication.

Remediation

Immediate Action: Review the official uxper vendor portal for the latest theme release and update to a version beyond 1.3.7.1 immediately.

Proactive Monitoring: Monitor server access logs for anomalous requests targeting theme-specific endpoints or unauthorized attempts to perform administrative actions.

Compensating Controls: Deploy a Web Application Firewall (WAF) with rules configured to block unauthorized requests to theme-specific files and sensitive administrative paths.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

The severity of this vulnerability necessitates immediate attention from security administrators managing WordPress environments utilizing the Nuss theme. Because the flaw allows for unauthenticated access to restricted functions, it is critical to verify the current theme version and apply the vendor patch as soon as it is released. Until an update is applied, ensure that access to the WordPress dashboard and related backend directories is strictly restricted to authorized personnel.

More uxper CVEs

Sources

Originally found and disclosed by Aiden | Patchstack Bug Bounty Program, per the CVE Program record.