Pagelines [pagelines] < 1.4.7 (closed)
unknownBecause of this vulnerability, the attackers can have an administrator account on the target's website. Update the theme.
- Affected:
- up to 1.4.7
- Fixed in:
- 1.4.7
- Disclosed:
- Jan 22, 2015
theme
4 known security issues reported for the Pagelines WordPress theme. Most recent disclosed Jan 22, 2015.
Running Pagelines on your site? Check whether your installed version is affected.
Scan your site freeBecause of this vulnerability, the attackers can have an administrator account on the target's website. Update the theme.
The Pagelines Theme for WordPress is vulnerable to authorization bypass due to a missing capability check on the pagelines_ajax_save_option_callback function in versions up to, and including, 1.4.5. This makes it possible for unauthenticated attackers to escalate privileges and create administrator accounts.
The Pagelines Theme for WordPress is vulnerable to authorization bypass due to a missing capability check on the pagelines_ajax_save_option_callback function in versions up to, and including, 1.4.5. This makes it possible for unauthenticated attackers to escalate privileges and create administrator accounts.
The pagelines WordPress theme was affected by a Privilege escalation security vulnerability.
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free