ColibriWP Theme framework <= (Various Versions) - Missing Authorization
mediumThe ColibriWP Theme framework used by multiple themes for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'activate_plugin' AJAX action in various versions. This makes it possible for authenticated attackers, with subscriber-level access and above, to activate arbit...
- CVSS:
- 4.3
- Affected:
- up to 1.0.15
- Fixed in:
- 1.0.16
- Disclosed:
- Apr 26, 2024