Showing 1 vulnerability on this page for Hybrid Composer

Signals CISA KEV Ransomware Nuclei
framework-y vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

WordPress Hybrid Composer 1.4.6 Unauthenticated Settings Change

WordPress Hybrid Composer 1.4.6 contains an unauthenticated settings change vulnerability that allows unauthenticated attackers to modify WordPress options by exploiting the hc_ajax_save_option action. Attackers can send POST requests to the admin-ajax.php endpoint with the action parameter set to hc_ajax_save_option to enable user registration and set the default role to administrator, enabling account takeover.

CWE-306Jun 4, 2026
CVSS9.3v4.0EPSS0.347%PoCs1SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX