plugin

Wp Child Theme Generator Vulnerabilities

2 known security issues reported for the Wp Child Theme Generator WordPress plugin. Most recent disclosed Jun 20, 2024.

1 critical 1 medium

Running Wp Child Theme Generator on your site? Check whether your installed version is affected.

Scan your site free

WP Child Theme Generator <= 1.1.1 - Missing Authorization to Unauthenticated Child Theme Creation/Activation

medium

The WP Child Theme Generator plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the wctg_easy_child_theme() function in all versions up to, and including, 1.1.1. This makes it possible for unauthenticated attackers to create a blank child theme and activate it c...

CVSS:
5.3
Affected:
up to 1.1.1
Fixed in:
1.1.2
Disclosed:
Jun 20, 2024

CVE-2024-3610 on NVD →

WP Child Theme Generator <= 1.1.2 - Authenticated (Administrator+) Arbitrary File Upload

critical

The WP Child Theme Generator plugin for WordPress is vulnerable to arbitrary file uploads in all versions up to, and including, 1.1.2 due to insufficient file type checking in the wctg_custom_child_theme_process() function. This makes it possible for administrators to upload arbitrary files on the affected site's serve...

CVSS:
9.1
Affected:
up to 1.1.2
Fixed in:
1.1.3
Disclosed:
Nov 20, 2023

CVE-2023-47873 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database