OFFLINE
Awaiting data
Security intelligence
MinorCritical vulnerability

CVE-2026-88797 (CVSS 7.1)

NVD · officialPublished Sep 30, 2026Risk 23/100

The Vayu X WordPress theme before 1.0.6 does not perform any capability check on one of its AJAX actions and exposes the nonce guarding it to every logged-in user, allowing any authenticated user, such as a subscriber, to install and activate any hosted on the WordPress.org repository.

CVSS
7.1
AV:NetworkAC:LowPR:LowUI:NoneC:NoneI:HighA:Low

This record is attributed to NVD. Exploitation status and remediation guidance are kept separate from the vulnerability's technical severity.

Open primary source