Sydney <= 2.56 - Missing Authorization to Authenticated (Subscriber+) Limited Theme Options Update
mediumThe Sydney theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'activate_modules' function in all versions up to, and including, 2.56. This makes it possible for authenticated attackers, with Subscriber-level access and above, to activate or deactivate various...
- CVSS:
- 5.3
- Affected:
- up to 2.56
- Fixed in:
- 2.57
- Disclosed:
- Sep 16, 2025