PT-2026-81294 · Yootheme · Yootheme Pro

CVE-2026-77997

·

Published

2026-08-25

·

Updated

2026-08-25

CVSS v4.0

5.1

Medium

VectorAV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:N/AU:N/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions YOOtheme Pro versions 1.0.0 through 5.0.41
Description A missing access check allows authenticated users with com template editing permissions to access information about arbitrary modules, even if they lack the required com modules permissions.
Recommendations Update YOOtheme Pro to a version later than 5.0.41.

Fix

Improper Access Control

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-77997

Affected Products

Yootheme Pro