Junglewise Threat Intelligence

CVE-2026-2278: VW Writer Blog theme authorization bypass in customizer reset

CVE-2026-2278 · Severity: medium · CVSS 4.3 · Published 2026-09-19

Executive brief

The VW Writer Blog theme for WordPress allows authenticated subscribers to reset all theme customizer settings to defaults without proper permission verification. An attacker with a low-privilege subscriber account can erase theme customizations and branding, causing service disruption and potentially reverting security-relevant display settings.

Technical details

The 'vw_writer_blog_reset_all_settings' function is missing a capability check, allowing authenticated subscribers to perform an admin-level action. The vulnerability requires authentication and is triggered via the theme customizer reset endpoint. An attacker gains the ability to modify theme configuration, and a fix is available in version 1.3.9 and later.

Affected products

  • VW Themes VW Writer Blog up to 1.3.8

Timeline

  • 2026-09-19: disclosed

References