Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-14805— Consulting - Business, Finance WordPress Theme <= 6.7.16 - Authenticated (Subscriber+) Privilege Escalation via AJAX

Quick assessment

Affected
StylemixThemes Consulting - Business, Finance WordPress Theme
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

WordPress 的“Consulting”主题在 6.7.16 及之前版本中易受权限提升(Privilege Escalation)漏洞影响。该漏洞由以下两个缺陷共同导致: 1. 位于 中的 AJAX 端点,在未进行权限检查或 nonce 验证的情况下,接受任意 transient 键值。 2. 位于 中的开发者访问登录机制,在遗留字符串模式(legacy string mode)下,基于 transient 值进行用户身份认证,但缺乏适当的密码学验证。 这两个缺陷结合后,使得拥有订阅者(subscriber)

CVSS 8.8 · High
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-14805

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Consulting - Business, Finance WordPress Theme <= 6.7.16 - Authenticated (Subscriber+) Privilege Escalation via AJAX
Source: CVE Program / CVE List V5
Vulnerability Description
The Consulting theme for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 6.7.16. This is due to a combination of two flaws: (1) the masterstudy_ms_stm_set_discard_transient AJAX endpoint in admin/admin-notices/classes/STMHandler.php accepts an arbitrary transient key without capability checks or nonce validation, and (2) the developer access login mechanism in admin/classes/stm-theme-support.php authenticates users based on a transient value without proper cryptographic validation when in legacy string mode. This makes it possible for authenticated attackers, with subscriber-level access and above, to set the stm_developer_access_token transient to a known value (1), then authenticate as any existing user including administrators by visiting a specially crafted URL, thereby achieving full privilege escalation to administrator.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
特权管理不恰当
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
StylemixThemes Consulting - Business, Finance WordPress Theme 0 ~ 6.7.16 -

II. Public POCs for CVE-2026-14805

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-14805

登录查看更多情报信息。

Vendor Advisories for CVE-2026-14805 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-14805

No comments yet


Leave a comment