← WordPress Vulnerabilities
WordPress security by component

Gillion

Gillion is a WordPress component with 1 published CVE record in this archive. The latest tracked vulnerability was published Jul 27, 2026; the highest CVE/CNA score is 5.3.

Theme slug: gillion

CVE-2026-66477: Gillion exposes an unauthenticated privileged operation

Gillion through 4.13 permits an unauthenticated request to reach a theme operation without the required access-control check. The Patchstack CNA record does not disclose the endpoint, action, parameter, function, protected object or concrete operation, so the exact integrity or confidentiality impact remains unknown.

PublishedJul 27, 2026
Known safe version4.14
Safe version
Jul 27, 2026 CVE-2026-66477
Gillion exposes an unauthenticated privileged operation
Gillion through 4.13 permits an unauthenticated request to reach a theme operation without the required access-control check. The Patchstack CNA record does not disclose the endpoint, action, parameter, function, protected object or concrete operation, so the exact integrity or confidentiality impact remains unknown.
4.14
CVE5.3
NVDPending