Real Estate by Templatic (Unknown Version) - Cross-Site Request Forgery to Arbitrary File Upload
high
The Realestate theme for WordPress is vulnerable to arbitrary file uploads via CSRF due to missing or incorrect nonce validation in the 'upload-file.php' file. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.
- CVSS:
- 8.8
- Affected:
- up to *
- Fix:
- No patched version reported
- Disclosed:
- Mar 31, 2014
Realestate [realestate] < 100 (unfixed + closed)
unknown
The Realestate theme for WordPress is vulnerable to arbitrary file uploads via CSRF due to missing or incorrect nonce validation in the 'upload-file.php' file. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.
- Affected:
- up to 100
- Fix:
- No patched version reported
- Disclosed:
- Mar 31, 2014
Realestate [realestate] < 100 (unfixed)
unknown
The realestate WordPress theme was affected by a Templatic Theme CSRF File Upload security vulnerability.
- Affected:
- up to 100
- Fix:
- No patched version reported
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database