CVE-2018-21013: Upperthemes Swape

Critical severity, CVSS 9.8. EPSS: 2% chance of exploitation in the next 30 days.

The Swape theme before 1.2.1 for WordPress has incorrect access control, as demonstrated by allowing new administrator accounts via vectors involving xmlPath to wp-admin/admin-ajax.php.

Affected products

Published 2019-09-09. Last modified 2026-06-17.