WordPress Plugin Vulnerabilities
Themeco Cornerstone < 7.8.8 (Premium, bundled with X Theme) - Subscriber+ Arbitrary User Password Hash Disclosure
Description
The plugin does not enforce capability checks on one of its CSS-preview request handlers, and exposes the nonce needed to call it to every logged-in user on any wp-admin page, allowing any authenticated user to evaluate dynamic content tokens against arbitrary users and disclose their sensitive metadata including raw password hashes. This affects the premium Themeco Cornerstone page builder distributed bundled with the X Theme, not the unrelated free `cornerstone` plugin (v0.8.x) on the .org repository.
Proof of Concept
Affects Plugins
References
CVE
Classification
Type
SENSITIVE DATA DISCLOSURE
OWASP top 10
CWE
CVSS
Miscellaneous
Original Researcher
Real_King_Engine (ISAL FRAMEWORK)
Submitter
Real_King_Engine (ISAL FRAMEWORK)
Verified
Yes
WPVDB ID
Timeline
Publicly Published
2026-06-03 (about 21 days ago)
Added
2026-06-03 (about 20 days ago)
Last Updated
2026-06-22 (about 1 day ago)