← Terug naar overzicht

A critical unauthenticated privilege escalation vulnerability has been identified in the Jawn WordPress theme affecting versions 1.4.2 and below. The vulnerability allows unauthenticated attackers to escalate their privileges without any prior authentication, posing a significant security risk to WordPress sites using this theme. The flaw is tracked as CVE-2026-66648 and has been documented by both NVD and Patchstack. Sites running Jawn theme version 1.4.2 or earlier are advised to update immediately. No exploitation details have been publicly disclosed in the available content, but the unauthenticated nature of the attack vector makes it particularly dangerous. WordPress administrators should patch or disable the theme until a secure version is available.

Affected products

  • Jawn WordPress Theme <= 1.4.2

Related CVE's

  • CVE-2026-66648

Categories

  • Identity & Access
  • Web Technologies