Arbitrary Option Update Vulnerability Affects Materialis WordPress Theme
CVE-2023-3204
6.5MEDIUM
What is CVE-2023-3204?
The Materialis theme for WordPress contains a vulnerability that arises from inadequate authorization checks within the companion_disable_popup() function, which is executed through an AJAX action. This flaw allows authenticated attackers, even those with low privilege levels such as subscribers, to alter any site option to a numerical value, potentially leading to significant unwanted changes in site functionality and user experience. This issue affects all versions of the Materialis theme up to and including 1.1.24.
Affected Version(s)
Materialis * <= 1.1.24