WP Vulnerability WatchVulnerability data as of September 17, 2026

Vulnerability alerts / September 14, 2026

Vulnerability in Consulting — CVE-2026-14805

HighSeverity
CVSS 8.8
0.3%Estimated exploit probability
EPSS
10,000+ sitesInstalls
6.7.17Fixed in

What to do now

Update Consulting to 6.7.17 or later.

Affected versions

  • Everything up to and including 6.7.16

Affected: Consulting (theme, consulting)

Check: The theme on wordpress.org / Our record for Consulting

What the vulnerability is

The Consulting theme for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 6.7.16. This is due to a combination of two flaws: (1) the masterstudy_ms_stm_set_discard_transient AJAX endpoint in admin/admin-notices/classes/STMHandler.php accepts an arbitrary transient key without capability checks or nonce validation, and (2) the developer access login mechanism in admin/classes/stm-theme-support.php authenticates users based on a transient value without proper cryptographic validation when in legacy string mode. This makes it possible for authenticated attackers, with subscriber-level access and above, to set the stm_developer_access_token transient to a known value (1), then authenticate as any existing user including administrators by visiting a specially crafted URL, thereby achieving full privilege escalation to administrator.

This description is reproduced verbatim from the public vulnerability record.

Sources

Part of this record comes from Wordfence Intelligence. Original: https://www.wordfence.com/threat-intel/vulnerabilities/id/bc8dffc2-ae5b-4482-9eba-adc439a52c26
Copyright 2012-2026 Defiant Inc. / Full license text

This page is compiled automatically from public databases. Accuracy is not guaranteed; confirm against the vendor advisory before acting.

See other alerts