
CVE-2026-2518 The FastX theme for WordPress is vulnerable to unauthorized limited plugin installation and activation due to missing capability checks on the 'ultp_install_callback' a… https://www.cve.org/CVERecord?id=CVE-2026-2518
Post summary
The FastX WordPress theme contains missing capability checks that enable unauthorized plugin installations. No PoC, exploit code, patch, or evidence of active exploitation is reported.
