CVE-2026-66648: WordPress Jawn theme <= 1.4.2 - Privilege Escalation vulnerability
Published Aug 24, 2026
·Updated
Unauthenticated Privilege Escalation in Jawn <= 1.4.2 versions.
Affected Software
1 affected component
WordPress Jawn theme<=1.4.2
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Jawn themeto a version that resolves this vulnerability.Fixed in 1.4.2
Event History
Aug 24, 2026
CVE Published
via MITRE·11:54 AM
Data Sourced
via MITRE·11:54 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Who can exploit this issue?
The issue is described as unauthenticated, so an attacker does not need an existing WordPress account or other privileges to exploit it.
2
What is the potential impact if exploitation succeeds?
Successful exploitation can result in privilege escalation. The critical severity vector indicates potential high impact to confidentiality, integrity, and availability.
3
Which installations should be treated as affected?
Installations using the Jawn WordPress theme at version 1.4.2 or earlier should be treated as affected.