Privilege Escalation Vulnerability in Consulting Theme for WordPress by STM
CVE-2026-14805
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 15 September 2026
What is CVE-2026-14805?
The Consulting theme for WordPress has a vulnerability that allows privileged users to escalate their access rights due to inadequate security controls. Specifically, the AJAX endpoint accepts arbitrary transient keys without necessary capability checks or nonce validation. Additionally, the authentication mechanism relies on transient values without proper cryptographic validation in certain modes. This allows authenticated users with minimal access, such as subscribers, to manipulate the system and authenticate as any user, including administrators, through crafted requests. This poses a significant risk for WordPress site owners using affected versions of the theme.
Affected Version(s)
Consulting - Business, Finance WordPress Theme 0 <= 6.7.16