Executive brief
The JaviBola Custom Theme Test plugin for WordPress, which allows administrators to test different website themes, contains a security flaw that could allow an attacker to change the site's active theme. By tricking a site administrator into clicking a malicious link, an attacker can remotely modify the site's appearance without authorization. This could lead to website defacement or disruption of the user experience.
Technical details
The JaviBola Custom Theme Test plugin for WordPress is vulnerable to Cross-Site Request Forgery (CSRF) due to missing or incorrect nonce validation on its options page. This vulnerability affects all versions up to and including 2.0.5. An unauthenticated attacker can exploit this by crafting a forged request to modify the 'jbct_theme' option. Successful exploitation requires a site administrator to interact with a malicious link or visit a compromised page while authenticated. This allows the attacker to change the active theme of the WordPress site, potentially leading to unauthorized site modifications.
Affected products
- JaviBola JaviBola Custom Theme Test up to, and including, 2.0.5
Timeline
- 2026-05-20: advisory: NVD publication date
References
- https://plugins.trac.wordpress.org/browser/javibola-custom-theme/tags/2.0.5/javibola-custom-theme.php
- https://plugins.trac.wordpress.org/browser/javibola-custom-theme/tags/2.0.5/javibola-custom-theme.php
- https://plugins.trac.wordpress.org/browser/javibola-custom-theme/tags/2.0.5/javibola-custom-theme.php
- https://plugins.trac.wordpress.org/browser/javibola-custom-theme/trunk/javibola-custom-theme.php
- https://plugins.trac.wordpress.org/browser/javibola-custom-theme/trunk/javibola-custom-theme.php
- https://plugins.trac.wordpress.org/browser/javibola-custom-theme/trunk/javibola-custom-theme.php
- https://www.wordfence.com/threat-intel/vulnerabilities/id/68a8a277-2ea6-4d75-b8cd-4d20eb17b3aa?source=cve