Constructor WordPress Theme Missing Authorization Vulnerability in Clean Function
Vulnerability
A vulnerability exists in the Constructor theme for WordPress, in all versions through 1.6.5, allowing unauthorized data modification. This issue arises from a lack of capability checks in the clean() function, enabling authenticated attackers with Subscriber-level access or higher to initiate a theme cleaning process.
Impact
Exploitation of this vulnerability allows for unauthorized modification of theme data, specifically through the ability to trigger the clean() function, which removes certain theme options and content.
Added: Oct 3, 2025, 12:31 PM
Updated: Oct 3, 2025, 12:31 PM
Vulnerability Rating
Custom Algorithm
spread
0.0impact
0.6exploitability
5.9remediation
0.0relevance
0.7threat
3.2urgency
2.9incentive
1.7Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
