CVE-2026-88797: Vayu X < 1.0.6 - Subscriber+ Arbitrary WordPress.org Plugin Installation and Activation
The Vayu X WordPress theme before 1.0.6 does not perform any capability check on one of its AJAX actions and exposes the nonce guarding it to every logged-in user, allowing any authenticated user, such as a subscriber, to install and activate any hosted on the WordPress.org repository.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Vayu X WordPress themeto a version that resolves this vulnerability.Fixed in 1.0.6
Event History
Frequently Asked Questions
Which users can exploit this issue?
Any authenticated WordPress user can exploit it, including users with only the Subscriber role. An attacker needs a valid login account but does not need administrative capabilities.
What actions can an attacker perform through the vulnerable AJAX action?
They can install and activate arbitrary plugins hosted in the WordPress.org plugin repository. This could allow activation of functionality that site administrators did not intend to deploy.
Are sites using the theme’s default access controls protected?
No. The affected AJAX action lacks a capability check, and its nonce is exposed to every logged-in user. Restricting users to Subscriber-level permissions does not prevent exploitation.
What should be done if the theme cannot be updated immediately?
Limit or disable untrusted user accounts and review installed and active plugins for unexpected WordPress.org plugins. Because exploitation requires authentication, reducing access to logged-in accounts lowers exposure.