• Sign in

CVE-2015-9456

    CVE-2015-9456  
Description The orbisius-child-theme-creator plugin before 1.2.8 for WordPress has incorrect access control for file modification via the wp-admin/admin-ajax.php?action=orbisius_ctc_theme_editor_ajax&sub_cmd=save_file theme_1, theme_1_file, or theme_1_file_contents parameter.
Impact
  CVSS v2 : 4 MEDIUM  
Type
  CWE-732  
Attack Vector
CVSSv2 Vector : AV:N/AC:L/Au:S/C:N/I:P/A:N
Quick linksCVE, NVD, CERT, Metasploit, Exploit-db, Fulldisc, Bugtraq, Microsoft, Red Hat, Debian, GitHub code/issues, Google
References
http://cinu.pl/research/wp-plugins/mail_28c91eee00e8e4b5868ebc58b5b1f730.html
https://wordpress.org/plugins/orbisius-child-theme-creator/#developers
https://wpvulndb.com/vulnerabilities/8315
  • FAQ
  • Terms of service
  • Privacy policy