CVE-2025-4606

9.8

uxper · Sala - Startup & SaaS WordPress Theme

The Sala WordPress theme contains a privilege escalation vulnerability via unverified password changes, allowing unauthenticated attackers to perform account takeovers.

Executive summary

A critical privilege escalation vulnerability in the Sala WordPress theme allows unauthenticated attackers to hijack user accounts, posing a severe risk to site integrity and security.

Vulnerability

The vulnerability is identified as a failure to perform adequate capability checks during password change operations (CWE-620). This flaw allows an unauthenticated attacker to manipulate the password reset mechanism to gain unauthorized administrative access to the WordPress site.

Business impact

The potential for complete account takeover, including administrative accounts, creates a high risk of total site compromise. Given the CVSS score of 9.8, this vulnerability is critical, as it allows attackers to inject malicious content, exfiltrate sensitive data, or redirect traffic, leading to significant reputational damage and potential loss of user trust.

Remediation

Immediate Action: As no patched version is currently available, administrators should immediately deactivate the Sala theme or switch to a secure alternative until a vendor-supplied update is released.

Proactive Monitoring: Review WordPress user logs for unexpected password change events or the creation of new administrative accounts by unknown users.

Compensating Controls: Implement a Web Application Firewall (WAF) with rules configured to detect and block suspicious requests targeting password reset or user management endpoints.

Exploitation status

Public Exploit Available: Yes — a public proof-of-concept exists on GitHub.

Analyst recommendation

Due to the critical severity and the existence of public proof-of-concept code, this vulnerability presents an immediate danger to affected WordPress installations. Administrators must prioritize the removal or deactivation of this theme immediately, as there is currently no available patch to resolve the underlying security flaw.

More uxper CVEs