WP Child Theme Generator <= 1.1.1 - Missing Authorization to Unauthenticated Child Theme Creation/Activation
medium
The WP Child Theme Generator plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the wctg_easy_child_theme() function in all versions up to, and including, 1.1.1. This makes it possible for unauthenticated attackers to create a blank child theme and activate it c...
- CVSS:
- 5.3
- Affected:
- up to 1.1.1
- Fixed in:
- 1.1.2
- Disclosed:
- Jun 20, 2024
CVE-2024-3610 on NVD →
WP Child Theme Generator <= 1.1.2 - Authenticated (Administrator+) Arbitrary File Upload
critical
The WP Child Theme Generator plugin for WordPress is vulnerable to arbitrary file uploads in all versions up to, and including, 1.1.2 due to insufficient file type checking in the wctg_custom_child_theme_process() function. This makes it possible for administrators to upload arbitrary files on the affected site's serve...
- CVSS:
- 9.1
- Affected:
- up to 1.1.2
- Fixed in:
- 1.1.3
- Disclosed:
- Nov 20, 2023
CVE-2023-47873 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database