theme

Dailydeal Vulnerabilities

2 known security issues reported for the Dailydeal WordPress theme. Most recent disclosed Oct 23, 2013.

1 critical 1 high

Running Dailydeal on your site? Check whether your installed version is affected.

Scan your site free

Daily Deal (Unknown Versions) - Arbitrary File Upload

critical

The Daily Deal theme for WordPress is vulnerable to arbitrary file uploads due to missing file type validation via the /monetize/upload/ directory in unknown versions. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected sites server which may make remote code execution possibl...

CVSS:
9.8
Affected:
up to 2.2.4
Fix:
No patched version reported
Disclosed:
Oct 23, 2013

Dailydeal by Templatic < = 3.0.10 - Cross-Site Request Forgery to Arbitrary File Upload

high

The Dailydeal by Templatic theme for WordPress is vulnerable to arbitrary file uploads via CSRF due to missing or incorrect nonce validation in the 'upload-file.php' file in versions up to, and including, 3.0.10. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's serve...

CVSS:
8.8
Affected:
up to 3.0.10
Fix:
No patched version reported
Disclosed:
Oct 23, 2013

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database