Construction Light WordPress Theme Authentication Bypass Vulnerability Allowing Arbitrary Plugin Activation

Vulnerability

An authentication bypass vulnerability has been identified in the Construction Light WordPress theme, affecting versions prior to 1.6.8. The vulnerability arises from a lack of proper authorization and Cross-Site Request Forgery (CSRF) protection when activating plugins through an AJAX action. This flaw allows any authenticated user, including subscribers, to activate arbitrary plugins.

Impact

Exploitation of this vulnerability could lead to unauthorized activation of plugins by authenticated users, such as subscribers, potentially allowing them to execute malicious code or modify site functionality.

Reproduction

To reproduce this vulnerability, send a POST request to 'wp-admin/admin-ajax.php' with the action 'constructionlight_activate_plugin'. Include the 'slug' and 'file' parameters, specifying the plugin to be activated.

Remediation

Users are advised to update the Construction Light WordPress theme to version 1.6.8 or later.

Added: Dec 12, 2025, 6:20 AM
Updated: Dec 12, 2025, 6:20 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
6.6
remediation
7.7
relevance
1.5
threat
6.4
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.