CyberRota Analysis
AI-GeneratedThe Vayu X WordPress theme prior to version 1.0.6 lacks proper capability checks on an AJAX action, exposing a nonce that allows any authenticated user, including subscribers, to install and activate plugins from the WordPress.org repository. This vulnerability could lead to unauthorized plugin installations, potentially compromising site security and functionality. WordPress site administrators using this theme should prioritize updating to the latest version to mitigate the risk.
Original NVD Description
The Vayu X WordPress theme before 1.0.6 does not perform any capability check on one of its AJAX actions and exposes the nonce guarding it to every logged-in user, allowing any authenticated user, such as a subscriber, to install and activate any hosted on the WordPress.org repository.