CVE-2026-27435
MEDIUMWordPress Woffice theme < 5.4.33 - Broken Access Control vulnerability
Title source: cnaExploitation Summary
EIP tracks 1 public exploit for CVE-2026-27435. PoCs published by HermesNA-1.
AI-analyzed exploit summary This repository contains an auto-generated stub module for CVE-2026-27435, a missing authorization vulnerability in WofficeIO Woffice theme (versions before 5.4.33). The code includes placeholder methods (`check` and `run`) with no actual exploit implementation, only references to external sources for details.
Description
Missing Authorization vulnerability in WofficeIO Woffice allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Woffice: from n/a before 5.4.33.
Exploits (1)
This repository contains an auto-generated stub module for CVE-2026-27435, a missing authorization vulnerability in WofficeIO Woffice theme (versions before 5.4.33). The code includes placeholder methods (`check` and `run`) with no actual exploit implementation, only references to external sources for details.
References (1)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N