AdForest WordPress Theme Authentication Bypass Vulnerability

Vulnerability

A vulnerability allowing authentication bypass has been identified in the AdForest theme for WordPress, affecting all versions through 6.0.9. The issue arises because the theme does not adequately verify user identities before authentication, enabling unauthenticated attackers to log in as other users, including administrators, without a password.

Impact

Exploitation of this vulnerability allows unauthenticated users to gain administrative access on the affected WordPress site.

Remediation

Users are advised to update the AdForest theme to version 6.0.10 or a newer patched version.

Added: Sep 6, 2025, 3:22 AM
Updated: Sep 6, 2025, 3:22 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
5.0
exploitability
7.4
remediation
7.7
relevance
0.4
threat
0.0
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.