** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All references and descriptions in this candidate have been removed to prevent accidental usage.
No vendor fix or workaround currently provided.
OpenCVE Recommended Actions
- Enable or install a safe version of the Jawn theme (any release beyond 1.4.2 if available) or replace the theme entirely.
- If an immediate upgrade is not possible, disable or delete the Jawn theme to remove the vulnerable code from the site.
- Ensure WordPress core, all other themes, and plugins are updated to their latest secure releases to minimize related risks.
- Audit site user accounts for newly created administrators and revoke any unexpected accounts.
- Implement least‑privilege access controls, restricting the number of users with administrator rights and enabling two‑factor authentication for privileged accounts.
Generated by OpenCVE AI on August 25, 2026 at 06:35 UTC.
Tracking
Sign in to view the affected projects.
No advisories yet.
No reference.
Tue, 01 Sep 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Jawn <= 1.4.2 - Unauthenticated Privilege Escalation | |
| Weaknesses | CWE-266 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Tue, 01 Sep 2026 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Jawn theme for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.4.2. This makes it possible for unauthenticated attackers to elevate their privileges to that of an administrator. | ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All references and descriptions in this candidate have been removed to prevent accidental usage. |
Tue, 25 Aug 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 25 Aug 2026 06:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Mvpthemes
Mvpthemes jawn Wordpress Wordpress wordpress |
|
| Vendors & Products |
Mvpthemes
Mvpthemes jawn Wordpress Wordpress wordpress |
Tue, 25 Aug 2026 05:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Jawn theme for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.4.2. This makes it possible for unauthenticated attackers to elevate their privileges to that of an administrator. | |
| Title | Jawn <= 1.4.2 - Unauthenticated Privilege Escalation | |
| Weaknesses | CWE-266 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: REJECTED
Assigner: Wordfence
Published:
Updated: 2026-09-01T13:19:48.296Z
Reserved: 2026-08-24T16:53:08.840Z
Link: CVE-2026-78477
Updated:
Status : Rejected
Published: 2026-08-25T06:19:01.147
Modified: 2026-09-01T14:17:41.333
Link: CVE-2026-78477
No data.
OpenCVE Enrichment
Updated: 2026-08-25T06:45:03Z
No weakness.