Insufficient Option Restrictions in Stops Core Theme and Plugin Updates for WordPress
CVE-2019-15650
4.3MEDIUM
What is CVE-2019-15650?
The Stops Core Theme and Plugin Updates plugin for WordPress has a weakness stemming from inadequate restrictions on option changes, specifically concerning the disabling of unattended theme updates. This flaw arises from an error in the nonce verification process, which may lead to unauthorized modification of key settings in the plugin. Attackers could exploit this vulnerability to manipulate plugin behavior, potentially compromising the integrity of theme updates and overall site security.