PT-2015-4369 · Themepunch · Showbiz Pro+1
Published
2015-06-30
·
Updated
2016-11-28
·
CVE-2014-9735
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
ThemePunch Slider Revolution plugin versions prior to 3.0.96
Showbiz Pro plugin version 1.7.1 and earlier
Description
The issue allows remote attackers to upload and execute arbitrary files, delete arbitrary sliders, and create, update, import, or export arbitrary sliders due to improper access restriction to administrator AJAX functionality.
Recommendations
For ThemePunch Slider Revolution plugin versions prior to 3.0.96, update to version 3.0.96 or later.
For Showbiz Pro plugin version 1.7.1 and earlier, update to a version later than 1.7.1.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Showbiz Pro
Themepunch Slider Revolution