Executive brief
Capella is a WordPress theme used to build and customize website front-ends. An unauthenticated attacker can exploit a flaw in the theme to escalate privileges and gain full administrative control over a WordPress site, potentially allowing them to steal data, inject malicious code, or take the site offline.
Technical details
The vulnerability is a privilege escalation flaw in the Capella WordPress theme (versions <= 2.5.5) that allows unauthenticated attackers to gain administrative privileges. The exact mechanism is not detailed in the advisory, but the OWASP classification points to identification and authentication failures. No authentication is required to trigger the exploit, and affected sites running vulnerable versions are at immediate risk. No official patch is available at the time of disclosure; mitigation via third-party security plugins is the recommended interim solution.
Affected products
- WordPress Capella Theme <= 2.5.5
Timeline
- 2026-08-20: disclosed: Vulnerability disclosed on NVD and Patchstack
- 2026-01-05: other: Reported by Tran Nguyen Bao Khanh (VCI - VNPT Cyber Immunity)