Description
Unauthenticated Privilege Escalation in Capella <= 2.5.5 versions.
Published: 2026-08-20
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Capella WordPress theme contains an unauthenticated privilege escalation flaw that lets an attacker elevate privileges on a site using any version up to 2.5.5. This weakness is categorized as CWE-266, indicating improper access control.

Affected Systems

Site owners using WordPress with ThemeGoods Capella theme version 2.5.5 or earlier are vulnerable. The flaw affects the Capella theme from ThemeGoods, supplying the frontend interface for WordPress sites.

Risk and Exploitability

The flaw can be triggered by any visitor, with no authentication required, giving an attacker the potential to assume administrative capabilities. The CVSS score of 9.8 signals a critical severity, and while the EPSS score is not available, the high impact rating suggests that exploitation is likely if the site remains on an affected version. The vulnerability is not listed in CISA KEV, but the combination of high severity and lack of restrictions makes it a priority to address.

Generated by OpenCVE AI on August 20, 2026 at 21:20 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Capella theme to the latest available version from ThemeGoods.
  • If an immediate upgrade cannot be performed, disable the Capella theme until a patched version is released.
  • Review and restrict user role permissions, ensuring only authorized administrators can activate themes or manage sensitive settings.

Generated by OpenCVE AI on August 20, 2026 at 21:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 20 Aug 2026 14:15:00 +0000

Type Values Removed Values Added
First Time appeared Themegoods
Themegoods capella
Wordpress
Wordpress wordpress
Vendors & Products Themegoods
Themegoods capella
Wordpress
Wordpress wordpress

Thu, 20 Aug 2026 12:15:00 +0000

Type Values Removed Values Added
Description Unauthenticated Privilege Escalation in Capella <= 2.5.5 versions.
Title WordPress Capella theme <= 2.5.5 - Privilege Escalation vulnerability
Weaknesses CWE-266
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Themegoods Capella
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-08-20T15:19:28.954Z

Reserved: 2026-08-19T10:28:23.758Z

Link: CVE-2025-15689

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-08-20T12:16:31.890

Modified: 2026-08-20T16:17:05.893

Link: CVE-2025-15689

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-20T21:30:05Z

Weaknesses
  • CWE-266

    Incorrect Privilege Assignment