PT-2025-38145 · WordPress · Sydney
Dmitry Ignatyev
·
Published
2025-09-17
·
Updated
2025-09-17
·
CVE-2025-8999
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Sydney theme for WordPress versions prior to 2.57
Description
The Sydney theme for WordPress is susceptible to unauthorized data modification due to a missing capability check on the
activate modules() function. This allows authenticated attackers with Subscriber-level access or higher to activate or deactivate theme modules.Recommendations
Update the Sydney theme to version 2.57 or later.
As a temporary workaround, restrict access for users with Subscriber-level access or lower.
Fix
LPE
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Sydney