OCTOBER 6, 2026
Live Feed
Back to database
Case File

CVE-2026-66588

HIGH · CVSS 7.5

Source: NVD + CISA KEV + EPSS · Published 2026-10-06 · Last synced 2026-10-06

CyberRota Analysis

AI-Generated

The vulnerability affects The7 theme versions up to 14.2.2, allowing unauthenticated users to bypass access controls and potentially gain unauthorized access to sensitive resources. This could lead to data exposure or manipulation, making it critical for website administrators using affected versions to prioritize patching. Organizations leveraging The7 for their WordPress sites should address this issue promptly to mitigate risks associated with unauthorized access.

CVE
CVE-2026-66588
Severity
HIGH
CVSS
7.5
EPSS
N/A

Original NVD Description

Unauthenticated Broken Access Control in The7 <= 14.2.2 versions.