Description
The VW Writer Blog theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'vw_writer_blog_reset_all_settings' function in all versions up to, and including, 1.3.8. This makes it possible for authenticated attackers, with Subscriber-level access and above, to reset all theme customizer settings to their defaults.
Published: 2026-09-19
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized reset of theme customizer settings via authenticated Subscriber+
Action: Apply patch
AI Analysis

Impact

The VW Writer Blog theme for WordPress allows an authenticated user with Subscriber-level access and above to execute the vw_writer_blog_reset_all_settings function without a capability check. This results in the entire set of theme customizer options being restored to default values. As a consequence the site owner loses all theme configuration—such as colors, layouts, and site branding—which may disrupt the site’s appearance and functionality. No code execution or data exfiltration is possible, but the loss of configuration can be significant for site operators.

Affected Systems

Any installation of the VW Writer Blog theme version 1.3.8 or earlier on a WordPress site. The vulnerability is present in all versions up to 1.3.8 and does not apply to 1.3.9 or later. The affected vendor is vowelweb.

Risk and Exploitability

The CVSS score of 4.3 indicates moderate risk, but the EPSS score of less than 1% shows the likelihood of exploitation is very low. The vulnerability is not listed in CISA KEV. Because the flaw requires an authenticated user owning at least a Subscriber role, an attacker must first compromise WordPress credentials or elevate a legitimate user to a higher role. After gaining those privileges, the attacker can reset all theme settings. The lack of an immediate destructive outcome reduces urgency, yet the loss of configuration can lead to significant operational impact. The typical attack vector is through the WordPress admin interface by submitting a request that triggers the reset function.

Generated by OpenCVE AI on September 19, 2026 at 23:54 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to version 1.3.9 or later, where the capability check has been added.
  • Replace the current theme with the patched version in the WordPress admin, ensuring it is active before any further use.
  • Further constrain the Subscriber role or use a role editor plugin to remove ability to access theme customizer options, limiting potential for misuse.

Generated by OpenCVE AI on September 19, 2026 at 23:54 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 21 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
First Time appeared Vowelweb
Vowelweb vw Writer Blog
Wordpress
Wordpress wordpress
Vendors & Products Vowelweb
Vowelweb vw Writer Blog
Wordpress
Wordpress wordpress

Sat, 19 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sat, 19 Sep 2026 08:00:00 +0000

Type Values Removed Values Added
Description The VW Writer Blog theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'vw_writer_blog_reset_all_settings' function in all versions up to, and including, 1.3.8. This makes it possible for authenticated attackers, with Subscriber-level access and above, to reset all theme customizer settings to their defaults.
Title VW Writer Blog <= 1.3.8 - Missing Authorization to Authenticated (Subscriber+) Theme Settings Reset
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'}


Subscriptions

Vowelweb Vw Writer Blog
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-09-19T14:01:24.449Z

Reserved: 2026-02-10T14:11:13.038Z

Link: CVE-2026-2278

cve-icon Vulnrichment

Updated: 2026-09-19T13:54:34.453Z

cve-icon NVD

Status : Deferred

Published: 2026-09-19T08:16:53.610

Modified: 2026-09-21T13:33:33.387

Link: CVE-2026-2278

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T10:03:37Z

Weaknesses