Access Control Flaw in Orbisius Child Theme Creator Plugin for WordPress
CVE-2015-9456
6.5MEDIUM
Summary
The Orbisius Child Theme Creator plugin for WordPress, specifically versions prior to 1.2.8, is susceptible to an access control vulnerability that allows unauthorized file modifications. This flaw exists in the handling of requests to the wp-admin/admin-ajax.php endpoint, particularly the parameters related to theme editing. Attackers can exploit this vulnerability to manipulate theme files, potentially leading to further security breaches or unauthorized alterations to the site's appearance and functionality.
References
CVSS V3.1
Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved