WordPress VW Writer Blog 1.3.8: Cap Check Missing in Reset Settings
CVE-2026-2278 Published on September 19, 2026

VW Writer Blog <= 1.3.8 - Missing Authorization to Authenticated (Subscriber+) Theme Settings Reset
The VW Writer Blog theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'vw_writer_blog_reset_all_settings' function in all versions up to, and including, 1.3.8. This makes it possible for authenticated attackers, with Subscriber-level access and above, to reset all theme customizer settings to their defaults.

NVD

Timeline

Disclosed

Weakness Type

What is an AuthZ Vulnerability?

The software does not perform an authorization check when an actor attempts to access a resource or perform an action.

CVE-2026-2278 has been classified to as an AuthZ vulnerability or weakness.


Affected Versions

vowelweb VW Writer Blog: