
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-57685 is a Broken Access Control (Missing Authorization) vulnerability in the Martfury - WooCommerce Marketplace WordPress Theme affecting versions 3.2.8 and earlier. It allows authenticated users with subscriber-level privileges to perform unauthorized actions beyond their intended scope. The vulnerability was reported by Ananda Dhakal (Patchstack) on September 17, 2024, and published on June 29, 2026. It carries a CVSS v3.1 base score of 4.3 (Medium) (Patchstack, GitHub Advisory).
The vulnerability is classified as CWE-862 (Missing Authorization), meaning the theme fails to perform adequate authorization checks when a subscriber-level user attempts to access or modify restricted resources or settings. An authenticated attacker with only subscriber privileges can exploit this over the network with low attack complexity and no user interaction required. No specific technical write-up or proof-of-concept code has been publicly disclosed at this time (Patchstack, GitHub Advisory).
A subscriber-level authenticated user can modify data or settings within the Martfury theme that should be restricted to higher-privileged roles such as administrators. The impact is limited to integrity — there is no confidentiality or availability impact — meaning an attacker cannot read sensitive data or disrupt service, but can make unauthorized changes to theme-controlled functionality. The scope is unchanged, limiting the blast radius to the affected WordPress installation (Patchstack).
As of the time of publication, no official patched version of the Martfury theme has been confirmed — Patchstack notes "No official patch available" for the patched version field. Site owners should monitor the theme vendor (drfuri) for an updated release beyond version 3.2.8 and apply it immediately when available. In the interim, administrators should audit subscriber-level account permissions, consider restricting subscriber registrations if not required, and evaluate virtual patching solutions such as Patchstack to block exploitation attempts (Patchstack).
The vulnerability was discovered and disclosed by Ananda Dhakal of Patchstack, which assigned it a "Low" priority rating given its limited impact and low likelihood of exploitation. Patchstack noted that vulnerabilities of this class are sometimes used in mass-exploit campaigns targeting WordPress sites regardless of traffic size, though this specific CVE has not been observed in such campaigns (Patchstack).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."