Executive brief
A security vulnerability in the Sonaar theme for WordPress allows users with low-level 'Subscriber' accounts to upgrade their own permissions. This could allow an attacker to gain administrative control over the website, potentially leading to data theft, site defacement, or a total service outage. Site owners should update to the latest version immediately to prevent unauthorized access.
Technical details
A privilege escalation vulnerability exists in the Sonaar WordPress theme (versions 4.27.4 and below) due to incorrect privilege assignment (CWE-266). An attacker authenticated with low-level 'Subscriber' privileges can exploit this flaw over the network without user interaction. Successful exploitation allows the attacker to escalate their privileges, potentially gaining full administrative access to the WordPress environment. The vulnerability is addressed in version 4.27.5.
Affected products
- SONAAR MUSIC Sonaar <= 4.27.4
Timeline
- 2025-09-06: other: Reported by Tran Nguyen Bao Khanh (VCI - VNPT Cyber Immunity)
- 2025-10-06: disclosed: Initial disclosure by Patchstack
- 2026-06-17: advisory: NVD publication date