PT-2025-51680 · WordPress · Platform Theme
Published
2025-07-25
·
Updated
2025-12-16
·
CVE-2015-10143
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Platform theme for WordPress versions prior to 1.4.4
Description
The Platform theme for WordPress is susceptible to unauthorized data modification, potentially leading to privilege escalation. A missing capability check within the
ajax save options() function allows unauthenticated attackers to update arbitrary options on a WordPress site. This can be exploited to modify the default role for registration to administrator and enable user registration, granting attackers administrative access.Recommendations
Update to Platform theme for WordPress version 1.4.4 or later.
Exploit
Fix
LPE
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Platform Theme