Dimension [dimension] < 1.1 (closed)
unknown
WordPress Dimension theme is prone to a cross-site request forgery vulnerability. It allows an attacker to gain unauthorized access to the affected application by performing certain actions in the context of an authorized user's session.
Upgrade the theme.
- Affected:
- up to 1.1
- Fixed in:
- 1.1
- Disclosed:
- Nov 18, 2013
Dimension (Unknown Versions) - Cross-Site Request Forgery to Arbitrary File Upload
high
The Dimension theme for WordPress is vulnerable to Cross-Site Request Forgery. This is due to missing or incorrect nonce validation in the 'upload-handler.php' file. This makes it possible for unauthenticated attackers to gain otherwise restricted access to administrative actions via a forged request granted they can t...
- CVSS:
- 8.8
- Affected:
- up to *
- Fix:
- No patched version reported
- Disclosed:
- Nov 17, 2013
Dimension [dimension] < 100 (unfixed + closed)
unknown
The Dimension theme for WordPress is vulnerable to Cross-Site Request Forgery. This is due to missing or incorrect nonce validation in the 'upload-handler.php' file. This makes it possible for unauthenticated attackers to gain otherwise restricted access to administrative actions via a forged request granted they can t...
- Affected:
- up to 100
- Fix:
- No patched version reported
- Disclosed:
- Nov 17, 2013
Dimension [dimension] < 100 (unfixed)
unknown
The dimension WordPress theme was affected by a CSRF security vulnerability.
- Affected:
- up to 100
- Fix:
- No patched version reported
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database