
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-50007 is an Incorrect Privilege Assignment vulnerability in the Jthemes xSmart WordPress theme that allows authenticated attackers to escalate their privileges. It affects xSmart versions up to and including 1.2.9.4. The vulnerability was published on January 22, 2026, with the CVE assigned by Patchstack. It carries a CVSS v3.1 base score of 8.8 (High), as assessed by CISA-ADP (Feedly, Patchstack).
The vulnerability is classified as CWE-266 (Incorrect Privilege Assignment), meaning the xSmart theme incorrectly assigns or manages privilege levels for authenticated users. An attacker with low-level privileges can exploit this flaw over the network without requiring user interaction or elevated preconditions, allowing them to gain higher access rights within the WordPress installation. No detailed technical write-up or public proof-of-concept code has been published at this time (Feedly, Patchstack).
Successful exploitation allows an authenticated low-privileged attacker to escalate their privileges within the affected WordPress site, resulting in high confidentiality, integrity, and availability impacts. This could enable unauthorized access to sensitive site data, modification of site content or configuration, and potential disruption of service. In a WordPress context, privilege escalation could allow an attacker to gain administrator-level access, facilitating further compromise such as installing malicious plugins, creating backdoor accounts, or defacing the site (Feedly).
There is no evidence of active in-the-wild exploitation or a publicly available proof-of-concept exploit for CVE-2025-50007 at this time. The vulnerability has not been added to the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.017%, indicating a very low probability of exploitation in the near term (Feedly).
No patch has been confirmed as available for the xSmart theme at the time of disclosure. Organizations using Jthemes xSmart version 1.2.9.4 or earlier should consider disabling or removing the theme if it is not actively required. Administrators should audit user accounts for unexpected privilege changes, enforce the principle of least privilege, and monitor for suspicious administrative activity. Check with Jthemes for any updated theme versions that address this vulnerability (Feedly, Patchstack).
Wordfence noted this vulnerability in their weekly WordPress vulnerability report covering January 12–18, 2026, as part of broader coverage of WordPress theme and plugin security issues (Wordfence Blog). No significant additional vendor statements or notable researcher commentary have been identified beyond the initial Patchstack disclosure.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."