What the vulnerability does
01Description
The Aurum - WordPress & WooCommerce Shopping Theme theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'lab_1cl_demo_install_package_content' function in all versions up to, and including, 4.0.2. This makes it possible for authenticated attackers, with Subscriber-level access and above, to overwrite content with imported demo content.
Explanation of Vulnerability in Simple Terms
02Summary
The Aurum WordPress theme contains a missing authorization flaw that allows authenticated users with low privileges to modify site content they should not have access to. An attacker with a basic user account can alter data through unprotected endpoints. The vulnerability affects all versions up to 4.0.2. Site owners should update to a version newer than 4.0.2 to remediate the issue.
What an attacker can do
03Attacker Capabilities
Modify site content or settings without proper permission checks.
Potential impact on your site
04Site Impact
Unauthorized users can alter site data, potentially defacing content or changing settings.
Conditions required to exploit
05Prerequisites
Attacker needs a low-privilege WordPress user account (e.g., subscriber or contributor).
Key dates
06Disclosure timeline
January 7, 2025
CVE published
April 8, 2026
Record updated