Stops Core Theme And Plugin Updates <= 8.0.4 - Insufficient Restrictions on Option Changes
2019-03-28 00:00
AnonymousStrategic Overview
StatusPatched in 8.0.5
Affected PluginEasy Updates Manager
Affected Version
<= 8.0.4CVSS4.3Medium
CVE
CVE-2019-15650Vulnerability Overview
The stops-core-theme-and-plugin-updates plugin before 8.0.5 for WordPress has insufficient restrictions on option changes (such as disabling unattended theme updates) because of a nonce check error.
Technical Analysis
REMEDIATION: Update to version 8.0.5, or a newer patched version --- IDENTIFIER: CWE-285 (Improper Authorization) The product does not perform or incorrectly performs an authorization check when an actor attempts to access a resource or perform an action.
External References
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C