Executive brief
The VW Writer Blog theme for WordPress allows authenticated subscribers to reset all theme customizer settings to defaults without proper permission verification. An attacker with a low-privilege subscriber account can erase theme customizations and branding, causing service disruption and potentially reverting security-relevant display settings.
Technical details
The 'vw_writer_blog_reset_all_settings' function is missing a capability check, allowing authenticated subscribers to perform an admin-level action. The vulnerability requires authentication and is triggered via the theme customizer reset endpoint. An attacker gains the ability to modify theme configuration, and a fix is available in version 1.3.9 and later.
Affected products
- VW Themes VW Writer Blog up to 1.3.8
Timeline
- 2026-09-19: disclosed