CVE-2023-3204
20.06.2024, 02:15
The Materialis theme for WordPress is vulnerable to limited arbitrary options updates in versions up to, and including, 1.1.24. This is due to missing authorization checks on the companion_disable_popup() function called via an AJAX action. This makes it possible for authenticated attackers, with minimal permissions such as subscribers, to modify any option on the site to a numerical value.Enginsight
Vendor | Product | Version |
---|---|---|
extendthemes | materialis | 𝑥 < 1.1.30 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References