WordPress security by component
jawn
jawn is a WordPress theme with 2 published CVE records in this archive. The latest tracked vulnerability was published Aug 25, 2026; the highest published CVSS base score is 9.8.
Theme slug:
jawnLatest vulnerability
CVE-2026-78477: Jawn permits unauthenticated privilege escalation to Administrator
The Jawn theme through 1.4.2 permits an unauthenticated attacker to elevate privileges to Administrator, allowing full control of the WordPress site.
| Safe version |
|
||
|---|---|---|---|
| Aug 25, 2026 |
CVE-2026-78477
Jawn permits unauthenticated privilege escalation to Administrator
The Jawn theme through 1.4.2 permits an unauthenticated attacker to elevate privileges to Administrator, allowing full control of the WordPress site.
|
See mitigation notes |
CVE9.8
NVDPending
|
| Aug 24, 2026 |
CVE-2026-66648
Jawn permits unauthenticated privilege escalation
Jawn through 1.4.2 permits an unauthenticated attacker to cross a privilege boundary and obtain elevated access. The CNA rates the resulting confidentiality, integrity, and availability impact as high.
|
See mitigation notes |
CVE9.8
NVDPending
|