theme

Simpolio Vulnerabilities

3 known security issues reported for the Simpolio WordPress theme. Most recent disclosed Oct 10, 2019.

1 high

Running Simpolio on your site? Check whether your installed version is affected.

Scan your site free

Simpolio [simpolio] < 100 (unfixed + closed)

unknown

[en] The Simpolio theme 1.3.2 for WordPress has insufficient restrictions on option updates.

Affected:
up to 100
Fix:
No patched version reported
Disclosed:
Oct 10, 2019

CVE-2015-9474 on NVD →

Simpolio - Fullscreen Portfolio & Blog HTML Theme <= 1.3.2 - Arbitrary Options Update

high

The Simpolio - Fullscreen Portfolio & Blog HTML Theme theme for WordPress is vulnerable to arbitrary option updates due to a missing capability check on the of_ajax_post_action AJAX action in versions up to, and including, 2.1. This makes it possible for unauthenticated attackers to edit arbitrary site options which ca...

CVSS:
8.8
Affected:
up to 1.3.2
Fix:
No patched version reported
Disclosed:
Jun 26, 2015

CVE-2015-9474 on NVD →

Simpolio [simpolio] < 1.3.3

unknown

Because of this privilege escalation vulnerability, the attackers can update options and execute commands on the server. Update the theme.

Affected:
up to 1.3.3
Fixed in:
1.3.3
Disclosed:
Jun 26, 2015

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database