PT-2025-51680 · WordPress · Platform Theme

Published

2025-07-25

·

Updated

2025-12-16

·

CVE-2015-10143

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Platform theme for WordPress versions prior to 1.4.4
Description The Platform theme for WordPress is susceptible to unauthorized data modification, potentially leading to privilege escalation. A missing capability check within the ajax save options() function allows unauthenticated attackers to update arbitrary options on a WordPress site. This can be exploited to modify the default role for registration to administrator and enable user registration, granting attackers administrative access.
Recommendations Update to Platform theme for WordPress version 1.4.4 or later.

Exploit

Fix

LPE

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2015-10143

Affected Products

Platform Theme