CVE-2026-12471
Received Received - Intake

Spexo Theme WordPress Plugin Missing Capability Check

Vulnerability report for CVE-2026-12471, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-06-27

Last updated on: 2026-06-27

Assigner: Wordfence

Description

The Spexo theme for WordPress is vulnerable to unauthorized access due to a missing capability check on the activate_plugin function in all versions up to, and including, 2.0.11. This makes it possible for authenticated attackers, with Subscriber-level access and above, to activate a limited set of plugins.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-06-27
Last Modified
2026-06-27
Generated
2026-06-27
AI Q&A
2026-06-27
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
wp_themes spexo to 2.0.11 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-862 The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

The Spexo theme for WordPress has a vulnerability due to a missing capability check in its activate_plugin function in all versions up to and including 2.0.11.

This flaw allows authenticated users with Subscriber-level access or higher to activate certain plugins without proper authorization.

Impact Analysis

An attacker with Subscriber-level access or above can exploit this vulnerability to activate a limited set of plugins on the affected WordPress site.

This unauthorized activation could lead to potential security risks depending on the plugins activated, such as introducing malicious functionality or altering site behavior.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-12471. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart