Junglewise Threat Intelligence

CVE-2026-49113: THEMECO Cornerstone code injection allows arbitrary code execution

CVE-2026-49113 · Severity: high · CVSS 8.5 · Published 2026-06-17

Technologies: THEMECO Cornerstone. Vendors: THEMECO.

Executive brief

Cornerstone, a popular page builder plugin for WordPress, contains a security flaw that allows users with low-level 'Subscriber' accounts to execute arbitrary code on the server. This could lead to a complete takeover of the website, unauthorized access to sensitive data, or the installation of malware. Site administrators should update the plugin immediately to prevent potential mass-exploitation campaigns.

Technical details

A code injection vulnerability (CWE-94) exists in the THEMECO Cornerstone plugin for WordPress in versions prior to 7.8.8. The flaw allows an authenticated attacker with Subscriber-level permissions to execute arbitrary code on the hosting server. While the attack requires network access and a valid low-privilege account, the impact is high as it can lead to full system compromise and bypasses security boundaries (Scope: Changed). The vulnerability was addressed in version 7.8.8.

Affected products

  • THEMECO Cornerstone < 7.8.8

Timeline

  • 2026-04-23: other: Reported by Nguyen Ba Khanh
  • 2026-06-04: advisory: Initial disclosure by Patchstack
  • 2026-06-17: disclosed: NVD publication date

References

Related threats