{"id":"CVE-2026-2278","title":"The VW Writer Blog theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'vw_writer_blog_reset_all_settings' function in all versions up to, and including, 1.3.8","summary":"The VW Writer Blog theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'vw_writer_blog_reset_all_settings' function in all versions up to, and including, 1.3.8. This makes it po…","severity":"medium","cvss":4.3,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","cwe":["CWE-862"],"vendor":"vowelweb","product":"VW Writer Blog","affected":["vw_writer_blog <= 1.3.8"],"published":"2026-09-19","updated":"2026-09-21","sourceUpdated":"2026-09-21T13:33:33.387","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-2278","references":[{"url":"https://themes.trac.wordpress.org/browser/vw-writer-blog/1.3.6/functions.php#L487","label":"security@wordfence.com"},{"url":"https://themes.trac.wordpress.org/browser/vw-writer-blog/1.3.9/functions.php#L487","label":"security@wordfence.com"},{"url":"https://themes.trac.wordpress.org/browser/vw-writer-blog/trunk/functions.php#L487","label":"security@wordfence.com"},{"url":"https://www.wordfence.com/threat-intel/vulnerabilities/id/2b1751f0-d385-43f5-bf90-82479a9c6694?source=cve","label":"security@wordfence.com"}],"tags":["nvd","cve.org"],"epss":0.00196,"epssPercentile":0.09585,"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"partial","timestamp":"2026-09-19T13:24:17.195549Z"},"ingestedAt":"2026-09-19T07:59:56.113Z","slug":"CVE-2026-2278","body":"## Overview\n\nThe VW Writer Blog theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'vw_writer_blog_reset_all_settings' function in all versions up to, and including, 1.3.8. This makes it possible for authenticated attackers, with Subscriber-level access and above, to reset all theme customizer settings to their defaults.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":24,"depthScoreParts":{"impact":23.7,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}