Materialis <= 1.1.24 - Missing Authorization to Limited Arbitrary Options Update
medium
The Materialis theme for WordPress is vulnerable to limited arbitrary options updates in versions up to, and including, 1.1.24. This is due to missing authorization checks on the companion_disable_popup() function called via an AJAX action. This makes it possible for authenticated attackers, with minimal permissions su...
- CVSS:
- 6.5
- Affected:
- up to 1.1.24
- Fixed in:
- 1.1.30
- Disclosed:
- Jun 19, 2024
CVE-2023-3204 on NVD →
Mesmerize <= 1.6.89 & Materialis <= 1.0.172 - Authenticated Arbitrary Options Update
high
The Mesmerize & Materialis themes for WordPress are vulnerable to authenticated options change in versions up to, and including,1.6.89 (Mesmerize) and 1.0.172 (Materialis). This is due to 'companion_disable_popup' function only checking the nonce while sending user input to the 'update_option' function. This makes it p...
- CVSS:
- 8.8
- Affected:
- up to 1.0.172
- Fixed in:
- 1.0.173
- Disclosed:
- Dec 2, 2019
CVE-2019-25142 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database