← Terug naar overzicht

The Jawn theme for WordPress contains a critical Privilege Escalation vulnerability affecting all versions up to and including 1.4.2. Unauthenticated attackers can exploit this flaw to elevate their privileges to administrator level, posing a severe risk to affected WordPress installations. No authentication is required to exploit this vulnerability, making it particularly dangerous. The vulnerability has been documented by both Patchstack and Wordfence security researchers. WordPress site administrators using the Jawn theme should update to a patched version immediately. The CVE identifier assigned is CVE-2026-78477. The issue represents a significant access control failure within the theme's code. Sites running vulnerable versions are at risk of full administrative compromise.

Affected products

  • Jawn WordPress Theme <= 1.4.2

Related CVE's

  • CVE-2026-78477

Categories

  • Identity & Access
  • Web Technologies