Vernissage <= 1.2.9 - Arbitrary Options Update
highThe Vernissage theme for WordPress is vulnerable to arbitrary option updates due to a missing capability check on the of_ajax_post_action AJAX action in versions up to, and including, 2.1. This makes it possible for unauthenticated attackers to edit arbitrary site options which can be used to create administrator accou...
- CVSS:
- 8.8
- Affected:
- up to 1.2.9
- Fixed in:
- 1.3
- Disclosed:
- Jun 26, 2015