PT-2026-42079 · WordPress · Javibola Custom Theme Test

Ibnu

+1

·

Published

2026-05-20

·

Updated

2026-05-28

·

CVE-2026-8423

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions JaviBola Custom Theme Test versions prior to 2.0.6
Description The JaviBola Custom Theme Test plugin for WordPress contains a Cross-Site Request Forgery (CSRF) flaw, which occurs when a web application allows an attacker to induce a user to perform actions they did not intend to. This issue is caused by missing or incorrect nonce validation on the options page. Unauthenticated attackers can change the active theme of a site by modifying the jbct theme option through a forged request, provided they can trick a site administrator into clicking a link.
Recommendations Update to a version newer than 2.0.5.

Fix

CSRF

Weakness Enumeration

Related Identifiers

CVE-2026-8423

Affected Products

Javibola Custom Theme Test