theme

Construct Vulnerabilities

8 known security issues reported for the Construct WordPress theme. Most recent disclosed Jun 30, 2015.

2 high

Running Construct on your site? Check whether your installed version is affected.

Scan your site free

Construct [construct] < 2.8.3

unknown

[en] The ThemePunch Slider Revolution (revslider) plugin before 3.0.96 for WordPress and Showbiz Pro plugin 1.7.1 and earlier for Wordpress does not properly restrict access to administrator AJAX functionality, which allows remote attackers to (1) upload and execute arbitrary files via an update_plugin action; (2) dele...

Affected:
up to 2.8.3
Fixed in:
2.8.3
Disclosed:
Jun 30, 2015

CVE-2014-9735 on NVD →

Construct [construct] < 2.8.3

unknown

[en] Directory traversal vulnerability in the Elegant Themes Divi theme for WordPress allows remote attackers to read arbitrary files via a .. (dot dot) in the img parameter in a revslider_show_image action to wp-admin/admin-ajax.php. NOTE: this vulnerability may be a duplicate of CVE-2014-9734.

Affected:
up to 2.8.3
Fixed in:
2.8.3
Disclosed:
Feb 11, 2015

CVE-2015-1579 on NVD →

Construct <= 1.4 - Arbitrary File Download

high

The Construct Theme for WordPress is vulnerable to Arbitrary File Download in versions up to, and including, 1.4. This is due to the '_mysite_download_skin' parameter in the 'dl-skin.php' file. This makes it possible for unauthenticated attackers to download any file within the server of the vulnerable service.

CVSS:
7.5
Affected:
up to 1.4
Fixed in:
1.5
Disclosed:
Dec 17, 2013

Construct <= 1.4 - Arbitrary File Deletion

high

The Construct Theme for WordPress is vulnerable to Arbitrary File Deletion in versions up to, and including, 1.4. This is due to the '_mysite_delete_skin_zip' parameter in the 'dl-skin.php' file. This makes it possible for unauthenticated attackers to delete any file on the server of the vulnerable service.

CVSS:
7.5
Affected:
up to 1.4
Fixed in:
1.5
Disclosed:
Dec 17, 2013

Construct [construct] < 1.5 (closed)

unknown

The Construct Theme for WordPress is vulnerable to Arbitrary File Download in versions up to, and including, 1.4. This is due to the '_mysite_download_skin' parameter in the 'dl-skin.php' file. This makes it possible for unauthenticated attackers to download any file within the server of the vulnerable service.

Affected:
up to 1.5
Fixed in:
1.5
Disclosed:
Dec 17, 2013

Construct [construct] < 1.5 (closed)

unknown

The Construct Theme for WordPress is vulnerable to Arbitrary File Deletion in versions up to, and including, 1.4. This is due to the '_mysite_delete_skin_zip' parameter in the 'dl-skin.php' file. This makes it possible for unauthenticated attackers to delete any file on the server of the vulnerable service.

Affected:
up to 1.5
Fixed in:
1.5
Disclosed:
Dec 17, 2013

Construct [construct] < 1.5

unknown

The construct WordPress theme was affected by a dl-skin.php _mysite_download_skin Parameter Absolute Path Traversal Remote File Download security vulnerability.

Affected:
up to 1.5
Fixed in:
1.5

Construct [construct] < 2.5

unknown

The construct WordPress theme was affected by a dl-skin.php _mysite_delete_skin_zip Parameter Absolute Path Traversal Remote Directory Deletion security vulnerability.

Affected:
up to 2.5
Fixed in:
2.5

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database