Euclid [euclid] < 1.0.1 (closed)
unknown
WordPress Euclid theme is prone to a cross-site request forgery vulnerability. It allows an attacker to gain unauthorized access to the affected application by performing certain actions in the context of an authorized user's session.
Upgrade the theme.
- Affected:
- up to 1.0.1
- Fixed in:
- 1.0.1
- Disclosed:
- Nov 18, 2013
Euclid <= All Versions - Cross-Site Request Forgery
high
The Euclid Theme for WordPress is vulnerable to Cross-Site Request Forgery in all versions. This is due to missing or incorrect nonce validation on the upload-handler function. This makes it possible for unauthenticated attackers to upload arbitrary files via a forged request granted they can trick a site administrator...
- CVSS:
- 8.8
- Affected:
- up to *
- Fix:
- No patched version reported
- Disclosed:
- Nov 17, 2013
Euclid [euclid] < 100 (unfixed + closed)
unknown
The Euclid Theme for WordPress is vulnerable to Cross-Site Request Forgery in all versions. This is due to missing or incorrect nonce validation on the upload-handler function. This makes it possible for unauthenticated attackers to upload arbitrary files via a forged request granted they can trick a site administrator...
- Affected:
- up to 100
- Fix:
- No patched version reported
- Disclosed:
- Nov 17, 2013
Euclid [euclid] < 100 (unfixed)
unknown
The euclid WordPress theme was affected by a CSRF security vulnerability.
- Affected:
- up to 100
- Fix:
- No patched version reported
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database