PT-2026-42079 · WordPress · Javibola Custom Theme Test
Ibnu
+1
·
Published
2026-05-20
·
Updated
2026-05-28
·
CVE-2026-8423
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
JaviBola Custom Theme Test versions prior to 2.0.6
Description
The JaviBola Custom Theme Test plugin for WordPress contains a Cross-Site Request Forgery (CSRF) flaw, which occurs when a web application allows an attacker to induce a user to perform actions they did not intend to. This issue is caused by missing or incorrect nonce validation on the options page. Unauthenticated attackers can change the active theme of a site by modifying the
jbct theme option through a forged request, provided they can trick a site administrator into clicking a link.Recommendations
Update to a version newer than 2.0.5.
Fix
CSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Javibola Custom Theme Test