Privilege Escalation Vulnerability in Vikinger Theme by WordPress
CVE-2025-2238
8.8HIGH
What is CVE-2025-2238?
The Vikinger theme for WordPress contains a vulnerability that allows authenticated users with subscriber-level access or higher to escalate their privileges to administrator level. This issue arises from inadequate restrictions on user metadata within the 'vikinger_user_meta_update_ajax' function, potentially exposing sensitive site operations to unauthorized users. Users of the Vikinger theme are advised to review their plugin versions and apply necessary patches to safeguard against this exploit.
Affected Version(s)
Vikinger * <= 1.9.30