{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3astylemixthemesconsulting/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:stylemixthemes:consulting:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":8.8,"id":"CVE-2026-14805"}],"_cs_exploited":false,"_cs_has_poc":true,"_cs_poc_references":["https://sploitus.com/exploit?id=CVE-2026-14805\u0026utm_source=rss\u0026utm_medium=rss"],"_cs_products":["Consulting (\u003c= 6.7.16)"],"_cs_severities":["high"],"_cs_tags":["wordpress","web-application","privilege-escalation"],"_cs_type":"advisory","_cs_vendors":["StylemixThemes"],"content_html":"\u003cp\u003eThe Consulting theme for WordPress (up to and including version 6.7.16) is susceptible to privilege escalation due to insecure implementation of AJAX endpoints and developer access login mechanisms. The vulnerability stems from two primary issues in the theme's codebase: the \u003ccode\u003emasterstudy_ms_stm_set_discard_transient\u003c/code\u003e AJAX action in \u003ccode\u003eadmin/admin-notices/classes/STMHandler.php\u003c/code\u003e lacks capability checks and nonce validation, and the login logic in \u003ccode\u003eadmin/classes/stm-theme-support.php\u003c/code\u003e relies on a transient value for authentication that can be bypassed if the site is in legacy string mode. An attacker with minimal subscriber-level access can set the \u003ccode\u003estm_developer_access_token\u003c/code\u003e transient to a known value and subsequently trigger the authentication mechanism to impersonate any user, including administrators. This allows for full administrative access to the WordPress site.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker obtains a standard subscriber-level account on the target WordPress site.\u003c/li\u003e\n\u003cli\u003eAttacker crafts a request to the \u003ccode\u003emasterstudy_ms_stm_set_discard_transient\u003c/code\u003e AJAX endpoint.\u003c/li\u003e\n\u003cli\u003eAttacker injects a value for the \u003ccode\u003estm_developer_access_token\u003c/code\u003e transient via the unprotected endpoint.\u003c/li\u003e\n\u003cli\u003eAttacker navigates to the endpoint handled by \u003ccode\u003eadmin/classes/stm-theme-support.php\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eThe application validates the transient value as a sufficient condition for authentication in legacy mode.\u003c/li\u003e\n\u003cli\u003eAttacker is granted a session as the target user.\u003c/li\u003e\n\u003cli\u003eAttacker performs administrative actions, such as installing malicious plugins or modifying site configuration.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation grants a low-privileged attacker full administrative control over the affected WordPress environment. This impact includes the potential for arbitrary code execution, sensitive data exfiltration, and full site takeover.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritized actions for security teams:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate the Consulting WordPress theme to the latest patched version immediately.\u003c/li\u003e\n\u003cli\u003eReview WordPress access logs for anomalous requests to the \u003ccode\u003eadmin-ajax.php\u003c/code\u003e endpoint containing \u003ccode\u003emasterstudy_ms_stm_set_discard_transient\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eAudit subscriber-level accounts for recent unauthorized activities or changes made to high-privilege user profiles.\u003c/li\u003e\n\u003cli\u003eMonitor for requests targeting \u003ccode\u003estm-theme-support.php\u003c/code\u003e paths within the web server logs.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-15T15:31:06Z","date_published":"2026-09-15T13:41:01Z","id":"https://feed.craftedsignal.io/briefs/2026-09-consulting-theme-privilege-escalation/","summary":"The Consulting theme for WordPress in versions 6.7.16 and earlier contains a vulnerability allowing authenticated users to escalate privileges to administrator by manipulating insecure transient-based authentication mechanisms.","title":"Privilege Escalation in Consulting Theme for WordPress via Improper Access Control","url":"https://feed.craftedsignal.io/briefs/2026-09-consulting-theme-privilege-escalation/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:stylemixthemes:consulting:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}