Child Theme Generator <= 2.2.7 Cross-Site Request Forgery to Arbitrary Folder Deletion
medium
The Child Theme Generator plugin for WordPress is vulnerability to Cross-Site Request Forgery in versions up to, and including, 2.2.7 due to insufficient nonce validation on the section_remove function. This makes it possible for attackers to delete arbitrary folders on the affected site, if they can successfully trick...
- CVSS:
- 5.4
- Affected:
- up to 2.2.7
- Fix:
- No patched version reported
- Disclosed:
- Nov 19, 2021
Child Theme Generator <= 2.2.7 - Reflected Cross-Site Scripting
medium
The Child Theme Generator WordPress plugin through 2.2.7 does not sanitise escape the parade parameter before outputting it back, leading to a Reflected Cross-Site Scripting in the admin dashboard
- CVSS:
- 6.4
- Affected:
- up to 2.2.7
- Fix:
- No patched version reported
- Disclosed:
- Nov 18, 2021
CVE-2021-24982 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database