Junglewise Threat Intelligence

CVE-2026-66648: Jawn Theme privilege escalation

CVE-2026-66648 · Severity: critical · CVSS 9.8 · Published 2026-08-24

Executive brief

Jawn is a WordPress theme used to build and manage websites. An unauthenticated attacker can exploit this vulnerability to escalate privileges and gain administrative control of an affected WordPress site, potentially leading to complete website compromise, data theft, and malicious redirection of site visitors.

Technical details

This is an unauthenticated privilege escalation vulnerability in the Jawn WordPress theme versions 1.4.2 and earlier. The vulnerability allows an attacker without any credentials or site access to escalate privileges to administrator level. The attack requires no user interaction and is network-accessible. Successful exploitation grants full administrative control of the WordPress installation. As of the advisory date, no official patch is available from the theme developer.

Affected products

  • Jawn Jawn Theme 1.4.2 and earlier

Timeline

  • 2026-08-20: disclosed: Vulnerability published by Patchstack
  • 2026-01-15: reported: Reported by Tran Nguyen Bao Khanh (VCI - VNPT Cyber Immunity)
  • 2026-08-24: advisory: CVE-2026-66648 published

References