PT-2019-7436 · WordPress · Vernissage
Published
2019-10-10
·
Updated
2019-10-15
·
CVE-2015-9477
CVSS v2.0
6.5
Medium
| Vector | AV:N/AC:L/Au:S/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Vernissage theme version 1.2.8
Description
The issue is related to insufficient restrictions on option updates in the Vernissage theme for WordPress.
Recommendations
For version 1.2.8, consider updating to a newer version that addresses the insufficient restrictions on option updates, or apply configuration changes to restrict option updates until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Incorrect Default Permissions
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Vernissage