Sceawere

Vulnerability Detail

CVE-2026-39721UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Starter Templates Missing Authorization Vulnerability

Vulnerability Metadata

Severity
Medium
Score / CVSS
5.4
Creation Date
10h ago
Vendor
Brainstorm Force
Product
Starter Templates
Attack Type
Missing Authorization
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L
Attack Complexity
LOW

Narrative and Response

Description

Missing Authorization vulnerability in Brainstorm Force Starter Templates astra-sites allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Starter Templates: from n/a through 4.7.7.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "5.4",
  "pubDate": "2026-10-05T09:17:13.227Z",
  "pubdate": "2026-10-05T09:17:13.227Z",
  "executiveSummary": "The Brainstorm Force Starter Templates plugin for WordPress is susceptible to a Missing Authorization vulnerability, formally categorized as an Improper Access Control issue. This vulnerability affects versions ranging from n/a through 4.7.7.\nThe flaw stems from the plugin's failure to adequately validate user permissions or access rights during the execution of sensitive administrative or functional requests. By failing to perform proper nonce or capability checks, the plugin allows unauthorized actors to perform actions that should be restricted to authenticated administrators.\nThe impact of this vulnerability is significant, as it permits attackers—potentially even unauthenticated users—to manipulate plugin settings or trigger internal processes without legitimate authorization. This leads to an escalation of privilege within the WordPress environment, potentially allowing for site reconfiguration, information disclosure, or the execution of unauthorized administrative functions.\nRisk implications are high for site integrity, as the exploitation does not require advanced technical prerequisites beyond identifying the insecurely exposed endpoints. To mitigate this risk, administrators should ensure the plugin is updated to a version beyond 4.7.7 or implement restrictive access controls at the application level if a patch is unavailable.",
  "technicalDetails": "The vulnerability resides within the internal request handling mechanisms of the Brainstorm Force Starter Templates plugin. The root cause is identified as an insufficient or missing implementation of authorization checks within the plugin's controller functions or AJAX handlers. Specifically, the affected code fails to verify the current user's security context—specifically the 'current_user_can()' capability check—before processing requests that alter system state or access sensitive resources.\nIn the context of the WordPress architecture, this indicates that the plugin provides an endpoint (likely via admin-ajax.php or a custom REST API route) that executes sensitive logic without verifying that the request originated from a user with administrative privileges (e.g., 'manage_options'). Because the developer failed to incorporate a nonce check and a capability validation step at the start of the execution flow, the application treats incoming requests as trusted by default.\nThe exploitation flow proceeds as follows: An attacker identifies a vulnerable request handler within the plugin's codebase. By crafting a specifically formatted HTTP POST or GET request directed at the plugin's vulnerable endpoint, the attacker can bypass standard access restrictions. Since no authorization token is verified, the server executes the associated function regardless of the requester's actual permission level. Depending on the specific function exposed, this could allow an attacker to overwrite site templates, reset plugin configurations, or perform unauthorized data modification.\nThe scope of this vulnerability is limited to the functionality provided by the Starter Templates plugin. The network exposure is broad, as these endpoints are typically reachable over the public internet, provided the WordPress installation is accessible. Because the vulnerability involves the logic of the plugin itself rather than the core WordPress platform, it manifests as a failure in secure coding practices during the implementation of the plugin's features. There are no complex exploitation requirements; the attacker simply needs to identify the URI endpoint and parameters required to trigger the desired action. Post-exploitation impact varies depending on the specific function abused, but generally involves a complete compromise of the plugin's functional integrity, which may serve as a precursor to further site-wide unauthorized changes."
}
CVE-2026-39721: Starter Templates Missing Authorization Vulnerability (MEDIUM Severity, CVSS: 5.4) | Sceawere