Sceawere

Vulnerability Detail

CVE-2026-102383UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Lookzy Plugin Missing Authorization Vulnerability

Vulnerability Metadata

Severity
Medium
Score / CVSS
6.5
Creation Date
2h ago
Vendor
VillaTheme
Product
Lookzy
Attack Type
Missing Authorization
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L
Attack Complexity
LOW

Narrative and Response

Description

Missing Authorization vulnerability in VillaTheme Lookzy woo-lookbook allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Lookzy: from n/a through 1.1.14.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "6.5",
  "pubDate": "2026-10-05T19:17:12.457Z",
  "pubdate": "2026-10-05T19:17:12.457Z",
  "executiveSummary": "The Lookzy woo-lookbook plugin for WordPress, within versions ranging from n/a through 1.1.14, contains a Missing Authorization vulnerability. This security flaw stems from improperly configured access control checks within the plugin's functional logic, allowing unauthorized actors to perform restricted actions that should be reserved for authenticated users with elevated privileges.\nThe vulnerability poses a significant risk to the integrity and confidentiality of the WordPress installation. An unauthenticated attacker can exploit this flaw by sending specifically crafted HTTP requests to the vulnerable endpoints. Because the plugin fails to perform adequate capability checks or verify user authentication before executing sensitive functions, attackers may perform unauthorized actions facilitated by the plugin's lookbook features.\nSuccessful exploitation does not require prior authentication, significantly lowering the barrier for entry. The potential impact ranges from unauthorized data modification or deletion to broader security compromises depending on the specific administrative functions improperly exposed. Organizations utilizing the affected version are exposed until the plugin access control logic is properly hardened or the plugin is updated to a patched version where authorization checks are correctly enforced.",
  "technicalDetails": "The vulnerability resides in the core architectural design of the VillaTheme Lookzy plugin, where critical administrative or data-manipulating functions lack necessary security validation protocols. Specifically, the plugin fails to implement robust checks to verify the current user's session status or capability level (e.g., 'manage_options' or similar administrative tokens) before processing requests directed toward sensitive plugin endpoints.\nIn a standard WordPress environment, administrative functionalities must be protected by function calls such as 'current_user_can()', which ensures the requester possesses the required permissions. The Lookzy plugin omits these checks in one or more of its handler functions. Consequently, the application processes incoming requests based solely on the presence of expected parameters, neglecting the authorization context of the request initiator.\nThe attack flow proceeds as follows: An attacker identifies an endpoint exposed by Lookzy that interacts with the backend database or performs configuration changes. The attacker crafts an HTTP request, typically a POST or GET request, targeting this endpoint. Because the application logic does not validate the sender's identity, the server executes the requested function with the same privileges as the plugin itself (often that of an administrator), rather than restricting the action based on the attacker's actual, unauthenticated or low-privilege status.\nThis vulnerability is classified as Missing Authorization (often mapped to CWE-862). The lack of input-independent authorization checks means that the vulnerability is triggered regardless of the input data, provided the request reaches the vulnerable function. The scope of the impact is highly dependent on the functionality exposed by the improperly secured code path; if the endpoint manages lookbook configuration or internal settings, the attacker can manipulate these settings, potentially leading to cross-site scripting (XSS) vectors if inputs are not properly sanitized, or unauthorized data destruction.\nThe attack is persistent across the specified version range of n/a through 1.1.14. Because the vulnerability exists in the plugin's server-side logic, it is remotely exploitable over the network without requiring any form of user interaction or administrative credential compromise. Post-exploitation impact is limited only by the permissions of the vulnerable function, which, in the context of WordPress plugins, often implies full access to the plugin's administrative settings."
}
CVE-2026-102383: Lookzy Plugin Missing Authorization Vulnerability (MEDIUM Severity, CVSS: 6.5) | Sceawere