Theme Editor, 9b660e2e-5cf8-4cf2-a307-989e150c37f9
- CVE, Research URL
- Home page URL
- Application
- Published on
- -
- Research Description
- Theme Editor [theme-editor] < 2.2 Theme Editor < 2.2 - Multiple Vulnerabilities Versions 2.1 and lower of the "theme-editor" plugin are affected by multiple vulnerabilities such as CSRF, insufficient permission checking, arbitrary file upload and the ability to interact with folders/files on the server in most ways you can imagine. These vulnerabilities (aside from CSRF) require access to any account, regardless of its role.
- Affected versions
-
max 2.2.
- Status
-
vulnerable