Executive brief
Chaplin is a WordPress theme used by website owners to customize the appearance and layout of their sites. This vulnerability allows unauthenticated attackers to access pages and perform actions they should not be permitted to, such as viewing other users' data or content, without requiring any login credentials. A successful exploit could expose sensitive information or allow unauthorized modifications to website content.
Technical details
The vulnerability is a broken access control flaw in the Chaplin WordPress theme affecting versions up to 2.6.8. The vulnerability does not require authentication, allowing any attacker with network access to exploit it. An attacker can access restricted pages or perform restricted actions through the theme, potentially exposing sensitive user data or allowing unauthorized operations. The issue has been patched in version 2.6.9. This is an OWASP Top 10 A1: Broken Access Control vulnerability.
Affected products
- WordPress Chaplin <=2.6.8
Timeline
- 2026-08-20: disclosed
- 2026-08-20: patched: Version 2.6.9 released with fix
- 2026-01-12: other: Initial report by Trương Hữu Phúc