WordPress VW Writer Blog 1.3.8: Cap Check Missing in Reset Settings
CVE-2026-2278 Published on September 19, 2026
VW Writer Blog <= 1.3.8 - Missing Authorization to Authenticated (Subscriber+) Theme Settings Reset
The VW Writer Blog theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'vw_writer_blog_reset_all_settings' function in all versions up to, and including, 1.3.8. This makes it possible for authenticated attackers, with Subscriber-level access and above, to reset all theme customizer settings to their defaults.
Timeline
Disclosed
Weakness Type
What is an AuthZ Vulnerability?
The software does not perform an authorization check when an actor attempts to access a resource or perform an action.
CVE-2026-2278 has been classified to as an AuthZ vulnerability or weakness.
Affected Versions
vowelweb VW Writer Blog:- Before and including 1.3.8 is affected.