Missing Authorization in ThemeHunk Th Shop Mania Affects Access Control
CVE-2026-105883

7.1HIGH

Key Information:

Vendor

WordPress

Vendor
CVE Published:
9 October 2026

What is CVE-2026-105883?

ThemeHunk's Th Shop Mania theme is prone to a missing authorization vulnerability due to incorrectly configured access control security levels. This flaw could allow unauthorized users to exploit functionalities or access sensitive information, potentially compromising the integrity of the site. Users are urged to upgrade to the latest version to safeguard against this issue.

Affected Version(s)

Th Shop Mania 0 <= 1.9.1

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

HaiND | Patchstack Bug Bounty Program
.