← WordPress Vulnerabilities
WordPress security by component

jawn

jawn is a WordPress theme with 2 published CVE records in this archive. The latest tracked vulnerability was published Aug 25, 2026; the highest published CVSS base score is 9.8.

Theme slug: jawn

CVE-2026-78477: Jawn permits unauthenticated privilege escalation to Administrator

The Jawn theme through 1.4.2 permits an unauthenticated attacker to elevate privileges to Administrator, allowing full control of the WordPress site.

PublishedAug 25, 2026
Safe version guidanceSee mitigation notes
Published vulnerabilities for jawn
Safe version
Aug 25, 2026 CVE-2026-78477
Jawn permits unauthenticated privilege escalation to Administrator
The Jawn theme through 1.4.2 permits an unauthenticated attacker to elevate privileges to Administrator, allowing full control of the WordPress site.
See mitigation notes
CVE9.8
NVDPending
Aug 24, 2026 CVE-2026-66648
Jawn permits unauthenticated privilege escalation
Jawn through 1.4.2 permits an unauthenticated attacker to cross a privilege boundary and obtain elevated access. The CNA rates the resulting confidentiality, integrity, and availability impact as high.
See mitigation notes
CVE9.8
NVDPending