Art Theme for WordPress Missing Capability Check Vulnerability Allowing Unauthorized Theme Option Deletion

Vulnerability

A vulnerability exists in the Art Theme for WordPress, in all versions through 3.12.2.3, due to a lack of proper capability checks in the 'arttheme_theme_option_restore' AJAX function. This flaw enables authenticated attackers with subscriber-level access or higher to delete specific theme options.

Impact

Exploitation of this vulnerability allows for unauthorized deletion of theme options, which could disrupt the site's appearance or functionality.

Remediation

Users are advised to update the Art Theme to version 3.12.3 or later.

Added: Sep 1, 2025, 7:22 PM
Updated: Sep 1, 2025, 7:22 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
0.6
exploitability
5.2
remediation
7.7
relevance
0.2
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.