← Back to CVE List
CVE-2026-2278NVD
Vulnerability Summary
The VW Writer Blog theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'vw_writer_blog_reset_all_settings' function in all versions up to, and including, 1.3.8. This makes it possible for authenticated attackers, with Subscriber-level access and above, to reset all theme customizer settings to their defaults.
CVSS v3.1 Base Metrics
Attack VectorNetwork
Attack ComplexityLow
Privileges RequiredLow
User InteractionNone
ScopeUnchanged
ConfidentialityNone
IntegrityLow
AvailabilityNone
External References
- https://www.wordfence.com/threat-intel/vulnerabilities/id/2b1751f0-d385-43f5-bf90-82479a9c6694?source=cve
- https://themes.trac.wordpress.org/browser/vw-writer-blog/1.3.6/functions.php#L487
- https://themes.trac.wordpress.org/browser/vw-writer-blog/trunk/functions.php#L487
- https://themes.trac.wordpress.org/browser/vw-writer-blog/1.3.9/functions.php#L487