CVE-2026-88797
Vayu X < 1.0.6 - Subscriber+ Arbitrary WordPress.org Plugin Installation and Activation
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
The Vayu X WordPress theme before 1.0.6 does not perform any capability check on one of its AJAX actions and exposes the nonce guarding it to every logged-in user, allowing any authenticated user, such as a subscriber, to install and activate any hosted on the WordPress.org repository.
| Vendor | unknown |
| Product | vayu x |
| Published | Sep 30, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown vayu x
Be the first to know when new unknown vulnerabilities affecting unknown vayu x are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / Vayu X
0 < 1.0.6
References
Credits
Xanlar Agamalizade WPScan