CVE-2026-78477: Jawn <= 1.4.2 - Unauthenticated Privilege Escalation
Published Aug 25, 2026
·Updated
The Jawn theme for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.4.2. This makes it possible for unauthenticated attackers to elevate their privileges to that of an administrator.
Affected Software
1 affected component
Jawn theme for WordPress<=1.4.2
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Jawn theme for WordPressto a version that resolves this vulnerability.Fixed in 1.4.2
Event History
Aug 25, 2026
CVE Published
via MITRE·05:31 AM
Data Sourced
via MITRE·05:31 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·06:19 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Who can exploit this issue?
An unauthenticated attacker can exploit it; no existing WordPress account or prior privileges are required.
2
What access could an attacker gain?
Successful exploitation can elevate the attacker’s privileges to administrator level.
3
Which installations are affected?
The affected software is the Jawn theme for WordPress, in all versions up to and including 1.4.2.