CVE-2026-14805: Consulting - Business, Finance WordPress Theme <= 6.7.16 - Authenticated (Subscriber+) Privilege Escalation via AJAX

Published Sep 15, 2026
·
Updated

The Consulting theme for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 6.7.16. This is due to a combination of two flaws: (1) the masterstudymsstmsetdiscardtransient AJAX endpoint in admin/admin-notices/classes/STMHandler.php accepts an arbitrary transient key without capability checks or nonce validation, and (2) the developer access login mechanism in admin/classes/stm-theme-support.php authenticates users based on a transient value without proper cryptographic validation when in legacy string mode. This makes it possible for authenticated attackers, with subscriber-level access and above, to set the stmdeveloperaccesstoken transient to a known value (1), then authenticate as any existing user including administrators by visiting a specially crafted URL, thereby achieving full privilege escalation to administrator.

Affected Software

1 affected component
WordPress Consulting (WordPress Theme)<=6.7.16

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade WordPress Consulting theme to a version that resolves this vulnerability.

    Fixed in 6.7.16
  2. Compensating control

    Restrict access to WordPress admin endpoints (especially admin/admin-notices/classes/STMHandler.php and admin/classes/stm-theme-support.php) to trusted users/IPs using a firewall/ACL or similar network-level restriction until the vulnerable theme version is updated.

Event History

Sep 15, 2026
CVE Published
via MITRE·01:03 PM
Data Sourced
via MITRE·01:03 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who can exploit this issue?

An attacker must already have an authenticated WordPress account with at least Subscriber-level access. They can then escalate to an administrator account, including any existing administrator user.

2

Does exploitation require user interaction or a difficult attack setup?

No user interaction is required, and the attack complexity is low. The attacker needs to issue an AJAX request to set the developer-access transient to a known value and then visit a specially crafted URL.

3

What versions are affected?

Consulting theme versions up to and including 6.7.16 are affected.

4

How can I determine whether exploitation may have occurred?

Review WordPress authentication and administrator-account activity for unexpected logins, particularly logins to existing administrator accounts from accounts that previously held only Subscriber-level access. Also investigate suspicious requests to the masterstudy_ms_stm_set_discard_transient AJAX endpoint and unexpected use of developer-access login URLs.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203