Description
** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All references and descriptions in this candidate have been removed to prevent accidental usage.
Published: 2026-08-25
Score: n/a
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All references and descriptions in this candidate have been removed to prevent accidental usage.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Enable or install a safe version of the Jawn theme (any release beyond 1.4.2 if available) or replace the theme entirely.
  • If an immediate upgrade is not possible, disable or delete the Jawn theme to remove the vulnerable code from the site.
  • Ensure WordPress core, all other themes, and plugins are updated to their latest secure releases to minimize related risks.
  • Audit site user accounts for newly created administrators and revoke any unexpected accounts.
  • Implement least‑privilege access controls, restricting the number of users with administrator rights and enabling two‑factor authentication for privileged accounts.

Generated by OpenCVE AI on August 25, 2026 at 06:35 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References

No reference.

History

Tue, 01 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Title Jawn <= 1.4.2 - Unauthenticated Privilege Escalation
Weaknesses CWE-266
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 01 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Description The Jawn theme for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.4.2. This makes it possible for unauthenticated attackers to elevate their privileges to that of an administrator. ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All references and descriptions in this candidate have been removed to prevent accidental usage.

Tue, 25 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 25 Aug 2026 06:45:00 +0000

Type Values Removed Values Added
First Time appeared Mvpthemes
Mvpthemes jawn
Wordpress
Wordpress wordpress
Vendors & Products Mvpthemes
Mvpthemes jawn
Wordpress
Wordpress wordpress

Tue, 25 Aug 2026 05:45:00 +0000

Type Values Removed Values Added
Description The Jawn theme for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.4.2. This makes it possible for unauthenticated attackers to elevate their privileges to that of an administrator.
Title Jawn <= 1.4.2 - Unauthenticated Privilege Escalation
Weaknesses CWE-266
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Mvpthemes Jawn
Wordpress Wordpress
cve-icon MITRE

Status: REJECTED

Assigner: Wordfence

Published:

Updated: 2026-09-01T13:19:48.296Z

Reserved: 2026-08-24T16:53:08.840Z

Link: CVE-2026-78477

cve-icon Vulnrichment

Updated:

cve-icon NVD

Status : Rejected

Published: 2026-08-25T06:19:01.147

Modified: 2026-09-01T14:17:41.333

Link: CVE-2026-78477

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-25T06:45:03Z

Weaknesses

No weakness.