Access Control Flaw in Orbisius Child Theme Creator Plugin for WordPress
CVE-2015-9456

6.5MEDIUM

Key Information:

Vendor
Wordpress
Vendor
CVE Published:
7 October 2019

Summary

The Orbisius Child Theme Creator plugin for WordPress, specifically versions prior to 1.2.8, is susceptible to an access control vulnerability that allows unauthorized file modifications. This flaw exists in the handling of requests to the wp-admin/admin-ajax.php endpoint, particularly the parameters related to theme editing. Attackers can exploit this vulnerability to manipulate theme files, potentially leading to further security breaches or unauthorized alterations to the site's appearance and functionality.

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.