Multiple Themes - Authenticated (Subscriber+) Arbitrary Plugin Activation and Deactivation
highSeveral themes are vulnerable to unauthorized access to functionality in various versions. This makes it possible for authenticated attackers, with Subscriber-level access and above, to activate or deactivate arbitrary plugins, which may make arbitrary code execution possible.
- CVSS:
- 8.8
- Affected:
- up to 1.4.2
- Fix:
- No patched version reported
- Disclosed:
- Nov 20, 2024