QAEngine <= 1.4 - Privilege Escalation
high
The QAEngine theme for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 1.4 via the 'class-ae-users.php' file and 'ae-sync-user' AJAX action. This makes it possible for authenticated attackers to gain access to an administrative account.
- CVSS:
- 8.8
- Affected:
- up to 1.4
- Fixed in:
- 1.5
- Disclosed:
- Apr 24, 2015
QAEngine [qaengine] < 1.5
unknown
The QAEngine theme for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 1.4 via the 'class-ae-users.php' file and 'ae-sync-user' AJAX action. This makes it possible for authenticated attackers to gain access to an administrative account.
- Affected:
- up to 1.5
- Fixed in:
- 1.5
- Disclosed:
- Apr 24, 2015
QAEngine [qaengine] < 1.6 (closed)
unknown
Because of this vulnerability, the attackers can have an administrator account on the target's website.
Update the theme.
- Affected:
- up to 1.6
- Fixed in:
- 1.6
- Disclosed:
- Apr 6, 2015
QAEngine [qaengine] <= 1.4 (unfixed)
unknown
QAEngine vulnerability allows an attacker to have an administrator account on the target's website.
- Affected:
- up to 1.4
- Fix:
- No patched version reported
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database