theme

Nightlife Vulnerabilities

4 known security issues reported for the Nightlife WordPress theme. Most recent disclosed Aug 1, 2014.

1 critical

Running Nightlife on your site? Check whether your installed version is affected.

Scan your site free

Nightlife [nightlife] < 1.1

unknown

Nightlife theme is prone to a cross-site request forgery vulnerability. It allows an attacker to gain unauthorized access to the affected application by performing certain actions in the context of an authorized user's session. Update the theme.

Affected:
up to 1.1
Fixed in:
1.1
Disclosed:
Aug 1, 2014

Nightlife Theme (All Known Versions) - Arbitrary File Upload

critical

The Nightlife Theme for WordPress is vulnerable to arbitrary file uploads due to missing file type validation via the upload-file.php file in all known versions. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected sites server which may make remote code execution possible.

CVSS:
9.8
Affected:
up to *
Fix:
No patched version reported
Disclosed:
Mar 31, 2014

Nightlife [nightlife] < 100 (unfixed + closed)

unknown

The Nightlife Theme for WordPress is vulnerable to arbitrary file uploads due to missing file type validation via the upload-file.php file in all known versions. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected sites server which may make remote code execution possible.

Affected:
up to 100
Fix:
No patched version reported
Disclosed:
Mar 31, 2014

Nightlife [nightlife] < 100 (unfixed)

unknown

The nightlife WordPress theme was affected by a Templatic Theme CSRF File Upload security vulnerability.

Affected:
up to 100
Fix:
No patched version reported

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database