Description
The Jawn theme for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.4.2. This makes it possible for unauthenticated attackers to elevate their privileges to that of an administrator.
Published: 2026-08-25
Score: 9.8 Critical
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Jawn theme for WordPress contains a flaw that allows an unauthenticated attacker to elevate privileges to administrator. The issue is rooted in the theme’s code, which improperly grants elevated rights, making it a binary, critical privilege escalation vulnerability (CWE‑266). An attacker can exploit the theme without any credentials and gain full control of the site’s backend.

Affected Systems

The vulnerability affects all installations of the MVPThemes Jawn theme through version 1.4.2. Any WordPress site that has a Jawn theme of that version or earlier is at risk. Site owners must verify their theme version and update or remove the theme if it falls within the affected range.

Risk and Exploitability

The CVSS score of 9.8 marks the vulnerability as critical. EPSS data is not available, so the likelihood of exploitation is uncertain but the unauthenticated nature suggests it could be high. The vulnerability is not listed in CISA KEV. The attack vector is through public web access to a WordPress site that has the vulnerable Jawn theme installed, allowing the attacker to trigger the code that grants administrator rights.

Generated by OpenCVE AI on August 25, 2026 at 06:35 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Enable or install a safe version of the Jawn theme (any release beyond 1.4.2 if available) or replace the theme entirely.
  • If an immediate upgrade is not possible, disable or delete the Jawn theme to remove the vulnerable code from the site.
  • Ensure WordPress core, all other themes, and plugins are updated to their latest secure releases to minimize related risks.
  • Audit site user accounts for newly created administrators and revoke any unexpected accounts.
  • Implement least‑privilege access controls, restricting the number of users with administrator rights and enabling two‑factor authentication for privileged accounts.

Generated by OpenCVE AI on August 25, 2026 at 06:35 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 25 Aug 2026 06:45:00 +0000

Type Values Removed Values Added
First Time appeared Mvpthemes
Mvpthemes jawn
Wordpress
Wordpress wordpress
Vendors & Products Mvpthemes
Mvpthemes jawn
Wordpress
Wordpress wordpress

Tue, 25 Aug 2026 05:45:00 +0000

Type Values Removed Values Added
Description The Jawn theme for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.4.2. This makes it possible for unauthenticated attackers to elevate their privileges to that of an administrator.
Title Jawn <= 1.4.2 - Unauthenticated Privilege Escalation
Weaknesses CWE-266
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Mvpthemes Jawn
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-08-25T05:31:29.287Z

Reserved: 2026-08-24T16:53:08.840Z

Link: CVE-2026-78477

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-25T06:19:01.147

Modified: 2026-08-25T06:19:01.147

Link: CVE-2026-78477

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-25T06:30:04Z

Weaknesses
  • CWE-266

    Incorrect Privilege Assignment