๐Ÿ” CVE Alert

CVE-2026-88797

UNKNOWN 0.0

Vayu X < 1.0.6 - Subscriber+ Arbitrary WordPress.org Plugin Installation and Activation

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

The Vayu X WordPress theme before 1.0.6 does not perform any capability check on one of its AJAX actions and exposes the nonce guarding it to every logged-in user, allowing any authenticated user, such as a subscriber, to install and activate any hosted on the WordPress.org repository.

Vendor unknown
Product vayu x
Published Sep 30, 2026
Stay Ahead of the Next One

Get instant alerts for unknown vayu x

Be the first to know when new unknown vulnerabilities affecting unknown vayu x are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Unknown / Vayu X
0 < 1.0.6

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wpscan.com: https://wpscan.com/vulnerability/250a7d7c-9c9b-4619-a6f4-533d29a30e23/

Credits

Xanlar Agamalizade WPScan