MinorCritical vulnerability
CVE-2026-88797 (CVSS 7.1)
NVD · officialPublished Sep 30, 2026Risk 23/100
The Vayu X WordPress theme before 1.0.6 does not perform any capability check on one of its AJAX actions and exposes the nonce guarding it to every logged-in user, allowing any authenticated user, such as a subscriber, to install and activate any hosted on the WordPress.org repository.
Technical details
CVSS
7.1
AV:NetworkAC:LowPR:LowUI:NoneC:NoneI:HighA:Low
Evidence and sources
This record is attributed to NVD. Exploitation status and remediation guidance are kept separate from the vulnerability's technical severity.
Open primary source