← Terug naar overzicht

A critical unauthenticated privilege escalation vulnerability has been identified in the Jawn WordPress theme affecting versions 1.4.2 and below. The vulnerability allows unauthenticated users to escalate their privileges, potentially gaining administrative access to affected WordPress installations. This type of vulnerability poses a significant risk as it requires no prior authentication to exploit. The issue is tracked as CVE-2026-66648 and has been documented by both the NVD and Patchstack. Users of the Jawn theme are advised to update to a patched version as soon as one becomes available. The vulnerability was disclosed through Patchstack's WordPress vulnerability database. No additional technical details about the exploitation method are provided in the current disclosure.

Affected products

  • Jawn WordPress Theme <= 1.4.2

Related CVE's

  • CVE-2026-66648

Categories

  • Identity & Access
  • Web Technologies