theme

Platform Vulnerabilities

2 known security issues reported for the Platform WordPress theme. Most recent disclosed Nov 23, 2016.

1 critical 1 high

Running Platform on your site? Check whether your installed version is affected.

Scan your site free

Platform 4 <= 1.1.4 - Cross-Site Request Forgery

high

The Platform 4 theme for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.4. This is due to missing or incorrect nonce validation in the 'includes/library.options.php' file. This makes it possible for unauthenticated attackers to gain otherwise restricted access to administrat...

CVSS:
8.8
Affected:
up to 1.1.4
Fix:
No patched version reported
Disclosed:
Nov 23, 2016

CVE-2016-10945 on NVD →

Platform < 1.4.4 - Missing Authorization to Unauthenticated Arbitrary Options Update

critical

The Platform theme for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on the *_ajax_save_options() function in all versions up to 1.4.4 (exclusive). This makes it possible for unauthenticated attackers to update arbitrary options on t...

CVSS:
9.8
Affected:
up to 1.4.4
Fixed in:
1.4.4
Disclosed:
Jan 21, 2015

CVE-2015-10143 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database