PT-2015-4369 · Themepunch · Showbiz Pro+1

Published

2015-06-30

·

Updated

2016-11-28

·

CVE-2014-9735

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions ThemePunch Slider Revolution plugin versions prior to 3.0.96 Showbiz Pro plugin version 1.7.1 and earlier
Description The issue allows remote attackers to upload and execute arbitrary files, delete arbitrary sliders, and create, update, import, or export arbitrary sliders due to improper access restriction to administrator AJAX functionality.
Recommendations For ThemePunch Slider Revolution plugin versions prior to 3.0.96, update to version 3.0.96 or later. For Showbiz Pro plugin version 1.7.1 and earlier, update to a version later than 1.7.1.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2014-9735

Affected Products

Showbiz Pro
Themepunch Slider Revolution