Quasar - WordPress Theme with Animation Builder <= 1.9.2 - Authorization Bypass
highThe Quasar Theme for WordPress is vulnerable to authorization bypass due to a missing capability check on the rock_builder_save_template function in versions up to, and including, 1.9.2. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to change settings and create admini...
- CVSS:
- 8.8
- Affected:
- up to 2.0
- Fixed in:
- 2.0
- Disclosed:
- Feb 2, 2015