Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2019-25142

Опубликовано: 07 июн. 2023
Источник: nvd
CVSS3: 8.8
EPSS Низкий

Описание

The Mesmerize & Materialis themes for WordPress are vulnerable to authenticated options change in versions up to, and including,1.6.89 (Mesmerize) and 1.0.172 (Materialis). This is due to 'companion_disable_popup' function only checking the nonce while sending user input to the 'update_option' function. This makes it possible for authenticated attackers to change otherwise restricted options.

Ссылки

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:extendthemes:materialis:*:*:*:*:*:wordpress:*:*
Версия до 1.0.173 (исключая)
cpe:2.3:a:extendthemes:mesmerize:*:*:*:*:*:wordpress:*:*
Версия до 1.6.90 (исключая)

EPSS

Процентиль: 63%
0.0044
Низкий

8.8 High

CVSS3

Дефекты

CWE-862

Связанные уязвимости

CVSS3: 8.8
github
больше 2 лет назад

The Mesmerize & Materialis themes for WordPress are vulnerable to authenticated options change in versions up to, and including,1.6.89 (Mesmerize) and 1.0.172 (Materialis). This is due to 'companion_disable_popup' function only checking the nonce while sending user input to the 'update_option' function. This makes it possible for authenticated attackers to change otherwise restricted options.

EPSS

Процентиль: 63%
0.0044
Низкий

8.8 High

CVSS3

Дефекты

CWE-862