Summary
CVE-2026-78477 is a critical incorrect privilege assignment (CWE-266) vulnerability in the Jawn WordPress theme by MVPThemes, affecting all versions up to and including 1.4.2. The flaw allows unauthenticated attackers to elevate their privileges to that of an administrator, resulting in full site compromise. It carries a CVSS v3.1 base score of 9.8 (Critical).
Technical details
- Root cause: incorrect privilege assignment (CWE-266) within the Jawn theme’s code
- Trigger conditions: no authentication or user interaction is required to exploit the flaw
- Attack vector: network — the theme can be targeted remotely over HTTP/HTTPS on any site running the affected code
- Impact: unauthenticated attackers can escalate their privileges to administrator level, enabling full compromise of confidentiality, integrity, and availability of the WordPress site
Affected software
- MVPThemes Jawn WordPress theme, versions 0 through 1.4.2 (inclusive)
Severity
- CVSS v3.1 Base Score: 9.8 (Critical)
- Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Mitigation and recommended actions
- Immediate: no patched version of the Jawn theme has been identified in available advisories; site owners should treat all versions up to 1.4.2 as vulnerable
- If no patch is available: remove or replace the Jawn theme, restrict administrative access, monitor sites for unauthorized administrator accounts, and watch vendor channels for an updated release before restoring the theme to production
How IONIX identifies potentially affected assets
IONIX matches the following signals against data already collected when it crawled the asset; identifying the technology sends no request beyond that crawl.
- Raw response body:
/wp-content/themes/jawn/

