Executive brief
The premium Cornerstone page builder plugin for WordPress, often bundled with the X Theme, contains a security flaw that allows any registered user to view sensitive information about other users. This includes private data such as user roles, session token fragments, and personal billing or shipping addresses. An attacker with a basic account could use this to gather intelligence for further attacks or compromise customer privacy.
Technical details
The Cornerstone plugin (specifically the premium version bundled with X Theme) lacks proper authorization checks on the '/themeco/data/dynamic-choices' REST API endpoint. An authenticated attacker with Subscriber-level privileges or higher can send a crafted, base64-encoded and gzipped JSON payload to this route to query user metadata. The vulnerability allows for the disclosure of sensitive 'usermeta' fields, including serialized capabilities (roles), session token prefixes, and WooCommerce billing/shipping information. While the returned metadata values are truncated to approximately 55 characters, they provide sufficient information for privilege escalation research or PII exposure. This issue is fixed in version 7.8.9.
Affected products
- Themeco Cornerstone (Premium) < 7.8.9
Timeline
- 2026-06-03: disclosed: Initial public disclosure by WPScan
- 2026-06-24: advisory: NVD publication date
- 2026-06-24: patched: Fixed in version 7.8.9