theme

Dimension Vulnerabilities

4 known security issues reported for the Dimension WordPress theme. Most recent disclosed Nov 18, 2013.

1 high

Running Dimension on your site? Check whether your installed version is affected.

Scan your site free

Dimension [dimension] < 1.1 (closed)

unknown

WordPress Dimension theme is prone to a cross-site request forgery vulnerability. It allows an attacker to gain unauthorized access to the affected application by performing certain actions in the context of an authorized user's session. Upgrade the theme.

Affected:
up to 1.1
Fixed in:
1.1
Disclosed:
Nov 18, 2013

Dimension (Unknown Versions) - Cross-Site Request Forgery to Arbitrary File Upload

high

The Dimension theme for WordPress is vulnerable to Cross-Site Request Forgery. This is due to missing or incorrect nonce validation in the 'upload-handler.php' file. This makes it possible for unauthenticated attackers to gain otherwise restricted access to administrative actions via a forged request granted they can t...

CVSS:
8.8
Affected:
up to *
Fix:
No patched version reported
Disclosed:
Nov 17, 2013

Dimension [dimension] < 100 (unfixed + closed)

unknown

The Dimension theme for WordPress is vulnerable to Cross-Site Request Forgery. This is due to missing or incorrect nonce validation in the 'upload-handler.php' file. This makes it possible for unauthenticated attackers to gain otherwise restricted access to administrative actions via a forged request granted they can t...

Affected:
up to 100
Fix:
No patched version reported
Disclosed:
Nov 17, 2013

Dimension [dimension] < 100 (unfixed)

unknown

The dimension WordPress theme was affected by a CSRF security vulnerability.

Affected:
up to 100
Fix:
No patched version reported

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database