Impact
The Jawn theme for WordPress contains a flaw that allows an unauthenticated attacker to elevate privileges to administrator. The issue is rooted in the theme’s code, which improperly grants elevated rights, making it a binary, critical privilege escalation vulnerability (CWE‑266). An attacker can exploit the theme without any credentials and gain full control of the site’s backend.
Affected Systems
The vulnerability affects all installations of the MVPThemes Jawn theme through version 1.4.2. Any WordPress site that has a Jawn theme of that version or earlier is at risk. Site owners must verify their theme version and update or remove the theme if it falls within the affected range.
Risk and Exploitability
The CVSS score of 9.8 marks the vulnerability as critical. EPSS data is not available, so the likelihood of exploitation is uncertain but the unauthenticated nature suggests it could be high. The vulnerability is not listed in CISA KEV. The attack vector is through public web access to a WordPress site that has the vulnerable Jawn theme installed, allowing the attacker to trigger the code that grants administrator rights.
OpenCVE Enrichment