Rocket Apps wProject Missing Authorization Vulnerability Allowing Unauthenticated Settings Changes

Vulnerability

A missing authorization vulnerability has been identified in the Rocket Apps wProject WordPress theme, affecting versions prior to 5.8.0. This vulnerability allows unauthenticated users to modify settings by deleting or altering post comments and attachments.

Impact

Exploitation of this vulnerability could lead to unauthorized changes in settings, allowing for the deletion or modification of post comments and attachments.

Remediation

Users are advised to update to version 5.8.0 or later. Patchstack has issued a virtual patch to mitigate this vulnerability until users can update.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
0.6
exploitability
7.4
remediation
7.7
relevance
0.0
threat
0.0
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.