The Materialis theme for WordPress... CVE-2023-3204

- AV AC AU C I A
发布: 2025-04-13
修订: 2025-04-13

The Materialis theme for WordPress is vulnerable to limited arbitrary options updates in versions up to, and including, 1.1.24. This is due to missing authorization checks on the companion_disable_popup() function called via an AJAX action. This makes it possible for authenticated attackers, with minimal permissions such as subscribers, to modify any option on the site to a numerical value.

0%
暂无可用Exp或PoC
当前有0条受影响产品信息