Beta

Report

Themify Ultra <= 7.3.5 is vulnerable to Multiple Broken Access Control vulnerability

Subscriber
Published
2023-11-09

The Themify Ultra theme for WordPress is vulnerable to unauthorized use of functionality due to a missing capability check on one of its functions in versions up to, and including, 7.3.5. This makes it possible for authenticated attackers, with subscriber-level access and above, to make use of this functionality.

CVSS

Score:8.3

Severity:High

Version: 7.3.5

There is a patch available in v7.3.6 and we strongly recommend you update to this version as soon as possible.