PT-2026-20597 · WordPress · Shopire+1

Ky0Tofu

·

Publicado

2026-02-19

·

Atualizado

2026-02-19

·

CVE-2025-13091

CVSS v3.1

4.3

Média

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Shopire theme for WordPress versions prior to 1.0.58
Description The Shopire theme for WordPress has an issue where data can be modified without authorization. This is due to a missing capability check within the shopire admin install plugin() function. Attackers with Subscriber-level access or higher can install the 'fable-extra' plugin.
Recommendations Update the Shopire theme to version 1.0.58 or later.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2025-13091

Produtos afetados

Shopire
Fable Extra