The Sala - Startup & SaaS WordPress Theme theme for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and in...
Description
The Sala - Startup & SaaS WordPress Theme theme for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 1.1.4. This is due to the theme not prope...
AI Analyst Comment
Remediation
Update The Sala Multiple Products to the latest version. Monitor for exploitation attempts and review access logs.
---METADATA---
VENDOR: uxper
PRODUCT: Sala - Startup & SaaS WordPress Theme
AFFECTED_VERSIONS: 0 through 1.1.4
CONFIDENCE: high
MISSING: patch
---END_METADATA---
Description Summary:
The Sala WordPress theme contains a privilege escalation vulnerability via unverified password changes, allowing unauthenticated attackers to perform account takeovers.
Executive Summary:
A critical privilege escalation vulnerability in the Sala WordPress theme allows unauthenticated attackers to hijack user accounts, posing a severe risk to site integrity and security.
Vulnerability Details
CVE-ID: CVE-2025-4606
Affected Software: uxper Sala - Startup & SaaS WordPress Theme
Affected Versions: 0 through 1.1.4
Vulnerability: The vulnerability is identified as a failure to perform adequate capability checks during password change operations (CWE-620). This flaw allows an unauthenticated attacker to manipulate the password reset mechanism to gain unauthorized administrative access to the WordPress site.
Business Impact
The potential for complete account takeover, including administrative accounts, creates a high risk of total site compromise. Given the CVSS score of 9.8, this vulnerability is critical, as it allows attackers to inject malicious content, exfiltrate sensitive data, or redirect traffic, leading to significant reputational damage and potential loss of user trust.
Remediation Plan
Immediate Action: As no patched version is currently available, administrators should immediately deactivate the Sala theme or switch to a secure alternative until a vendor-supplied update is released.
Proactive Monitoring: Review WordPress user logs for unexpected password change events or the creation of new administrative accounts by unknown users.
Compensating Controls: Implement a Web Application Firewall (WAF) with rules configured to detect and block suspicious requests targeting password reset or user management endpoints.
Exploitation Status
Public Exploit Available: Yes — a public proof-of-concept exists on GitHub.
Analyst Notes: As of July 9, 2025, there is no confirmed active exploitation in the wild; however, a public proof-of-concept is available via GitHub, making the exploitation risk highly credible. The lack of a vendor-provided patch increases the urgency for immediate mitigation via deactivation.
Analyst Recommendation
Due to the critical severity and the existence of public proof-of-concept code, this vulnerability presents an immediate danger to affected WordPress installations. Administrators must prioritize the removal or deactivation of this theme immediately, as there is currently no available patch to resolve the underlying security flaw.