Executive brief
Cornerstone, a popular page builder plugin for WordPress, contains a security flaw that allows users with low-level 'Subscriber' accounts to execute arbitrary code on the server. This could lead to a complete takeover of the website, unauthorized access to sensitive data, or the installation of malware. Site administrators should update the plugin immediately to prevent potential mass-exploitation campaigns.
Technical details
A code injection vulnerability (CWE-94) exists in the THEMECO Cornerstone plugin for WordPress in versions prior to 7.8.8. The flaw allows an authenticated attacker with Subscriber-level permissions to execute arbitrary code on the hosting server. While the attack requires network access and a valid low-privilege account, the impact is high as it can lead to full system compromise and bypasses security boundaries (Scope: Changed). The vulnerability was addressed in version 7.8.8.
Affected products
- THEMECO Cornerstone < 7.8.8
Timeline
- 2026-04-23: other: Reported by Nguyen Ba Khanh
- 2026-06-04: advisory: Initial disclosure by Patchstack
- 2026-06-17: disclosed: NVD publication date