Stops Core Theme And Plugin Updates <= 8.0.4 - Insufficient Restrictions on Option Changes

2019-03-28 00:00
Anonymous

Strategic Overview

Status
Patched in 8.0.5
Affected PluginEasy Updates Manager
Affected Version<= 8.0.4
CVSS4.3Medium
CVECVE-2019-15650
View all Easy Updates Manager vulnerabilities

Vulnerability Overview

The stops-core-theme-and-plugin-updates plugin before 8.0.5 for WordPress has insufficient restrictions on option changes (such as disabling unattended theme updates) because of a nonce check error.

Technical Analysis

REMEDIATION: Update to version 8.0.5, or a newer patched version --- IDENTIFIER: CWE-285 (Improper Authorization) The product does not perform or incorrectly performs an authorization check when an actor attempts to access a resource or perform an action.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C