CVE-2026-27435

MEDIUM

WordPress Woffice theme < 5.4.33 - Broken Access Control vulnerability

Title source: cna
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2026-27435. PoCs published by HermesNA-1.

AI-analyzed exploit summary This repository contains an auto-generated stub module for CVE-2026-27435, a missing authorization vulnerability in WofficeIO Woffice theme (versions before 5.4.33). The code includes placeholder methods (`check` and `run`) with no actual exploit implementation, only references to external sources for details.

Description

Missing Authorization vulnerability in WofficeIO Woffice allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Woffice: from n/a before 5.4.33.

Exploits (1)

github STUB 1 stars
by HermesNA-1 · pythonpoc
https://github.com/HermesNA-1/SnakeSploit/tree/main/data/modules_generated/cve-2026-27435_missing_authorization_vulnerability.py

This repository contains an auto-generated stub module for CVE-2026-27435, a missing authorization vulnerability in WofficeIO Woffice theme (versions before 5.4.33). The code includes placeholder methods (`check` and `run`) with no actual exploit implementation, only references to external sources for details.

Classification
Stub 99%
Attack Type
Auth Bypass
Complexity
Moderate
Reliability
Theoretical
Target: WofficeIO Woffice WordPress theme (versions before 5.4.33)
No auth needed
Prerequisites: Network access to the target WordPress site running vulnerable Woffice theme · Target must expose HTTP/HTTPS port
mistral-large-3 · analyzed Jul 09, 2026 Full analysis →

Scores

CVSS v3 5.3
EPSS 0.0024
EPSS Percentile 15.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-862
Status published
Products (1)
WofficeIO/Woffice < 5.4.33
Published Jul 01, 2026
Tracked Since Jul 01, 2026