cleantalk
Vulnerabilities and Security Researches

Theme Editor, 9b660e2e-5cf8-4cf2-a307-989e150c37f9

Application

Theme Editor

Published on
-
Research Description
Theme Editor [theme-editor] < 2.2 Theme Editor &lt; 2.2 - Multiple Vulnerabilities Versions 2.1 and lower of the &quot;theme-editor&quot; plugin are affected by multiple vulnerabilities such as CSRF, insufficient permission checking, arbitrary file upload and the ability to interact with folders/files on the server in most ways you can imagine. These vulnerabilities (aside from CSRF) require access to any account, regardless of its role.
Affected versions
max 2.2.
Status
vulnerable