CVE-2026-57685
WordPress vulnerability analysis and mitigation

Overview

CVE-2026-57685 is a Broken Access Control (Missing Authorization) vulnerability in the Martfury - WooCommerce Marketplace WordPress Theme affecting versions 3.2.8 and earlier. It allows authenticated users with subscriber-level privileges to perform unauthorized actions beyond their intended scope. The vulnerability was reported by Ananda Dhakal (Patchstack) on September 17, 2024, and published on June 29, 2026. It carries a CVSS v3.1 base score of 4.3 (Medium) (Patchstack, GitHub Advisory).

Technical details

The vulnerability is classified as CWE-862 (Missing Authorization), meaning the theme fails to perform adequate authorization checks when a subscriber-level user attempts to access or modify restricted resources or settings. An authenticated attacker with only subscriber privileges can exploit this over the network with low attack complexity and no user interaction required. No specific technical write-up or proof-of-concept code has been publicly disclosed at this time (Patchstack, GitHub Advisory).

Impact

A subscriber-level authenticated user can modify data or settings within the Martfury theme that should be restricted to higher-privileged roles such as administrators. The impact is limited to integrity — there is no confidentiality or availability impact — meaning an attacker cannot read sensitive data or disrupt service, but can make unauthorized changes to theme-controlled functionality. The scope is unchanged, limiting the blast radius to the affected WordPress installation (Patchstack).

Mitigation and workarounds

As of the time of publication, no official patched version of the Martfury theme has been confirmed — Patchstack notes "No official patch available" for the patched version field. Site owners should monitor the theme vendor (drfuri) for an updated release beyond version 3.2.8 and apply it immediately when available. In the interim, administrators should audit subscriber-level account permissions, consider restricting subscriber registrations if not required, and evaluate virtual patching solutions such as Patchstack to block exploitation attempts (Patchstack).

Community reactions

The vulnerability was discovered and disclosed by Ananda Dhakal of Patchstack, which assigned it a "Low" priority rating given its limited impact and low likelihood of exploitation. Patchstack noted that vulnerabilities of this class are sometimes used in mass-exploit campaigns targeting WordPress sites regardless of traffic size, though this specific CVE has not been observed in such campaigns (Patchstack).

Additional resources


SourceThis report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-10818HIGH8.1
  • wpforms
NoYesJul 25, 2026
CVE-2026-8789HIGH8.1
  • easy-appointments
NoYesJul 24, 2026
CVE-2026-14955MEDIUM6.5
  • woocommerce-checkout-field-editor-pro
NoYesJul 25, 2026
CVE-2026-15425MEDIUM6.4
  • wordpress-seo
NoYesJul 25, 2026
CVE-2026-15962NONEN/A
  • fluentformpro
NoYesJul 26, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management