Enable jQuery Migrate Helper Missing Authorization Vulnerability Allowing jQuery Downgrade

Vulnerability

A vulnerability exists in the Enable jQuery Migrate Helper plugin for WordPress, specifically in versions through 1.4.1. The issue arises from a lack of proper capability checks in the 'downgrade_jquery_version()' function, which only verifies a nonce. This flaw enables authenticated attackers with Subscriber-level access or higher to downgrade the global jQuery version from 3.7.1 to the outdated 1.12.4-wp version, known to contain security vulnerabilities.

Impact

Exploitation of this vulnerability allows for unauthorized downgrading of jQuery to a version with known security issues, potentially leading to exploitation of those vulnerabilities.

Reproduction

To reproduce this vulnerability, an authenticated user with Subscriber-level access or higher can send a request to the 'wp-admin/admin-ajax.php' endpoint. The request must include the 'action' parameter set to 'jquery-migrate-downgrade-version' and a valid nonce. This will trigger the downgrade of the jQuery version to 1.12.4-wp.

Added: May 27, 2026, 8:42 AM
Updated: May 27, 2026, 8:42 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
0.6
exploitability
6.3
remediation
0.0
relevance
9.7
threat
4.8
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.