PT-2026-7806 · WordPress · Adforest

·

CVE-2026-1729

·

Publicado

2026-02-12

·

Atualizado

2026-02-23

CVSS v3.1

9.8

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions AdForest versions up to and including 6.0.12
Description The AdForest theme for WordPress is susceptible to authentication bypass. The issue stems from insufficient user identity verification before authentication via the sb login user with otp fun function. This allows unauthenticated attackers to log in as any user, including administrators.
Recommendations Versions prior to and including 6.0.12 should be updated when a patch becomes available. As a temporary workaround, consider restricting access to the sb login user with otp fun function until a patch is available.

Correção

Missing Authentication

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-1729

Produtos afetados

Adforest