WordPress Plugin Vulnerabilities

Themeco Cornerstone < 7.8.8 (Premium, bundled with X Theme) - Subscriber+ Arbitrary User Password Hash Disclosure

Description

The plugin does not enforce capability checks on one of its CSS-preview request handlers, and exposes the nonce needed to call it to every logged-in user on any wp-admin page, allowing any authenticated user to evaluate dynamic content tokens against arbitrary users and disclose their sensitive metadata including raw password hashes. This affects the premium Themeco Cornerstone page builder distributed bundled with the X Theme, not the unrelated free `cornerstone` plugin (v0.8.x) on the .org repository.

Proof of Concept

Affects Plugins

Fixed in 7.8.8

References

Classification

Type
SENSITIVE DATA DISCLOSURE
CWE
CVSS

Miscellaneous

Original Researcher
Real_King_Engine (ISAL FRAMEWORK)
Submitter
Real_King_Engine (ISAL FRAMEWORK)
Verified
Yes

Timeline

Publicly Published
2026-06-03 (about 21 days ago)
Added
2026-06-03 (about 20 days ago)
Last Updated
2026-06-22 (about 1 day ago)

Other