BBE < 1.53 - Authorization Bypass

2018-05-10 00:00
Anonymous

Strategic Overview

Status
Patched in 1.53
Affected ThemeBBE
Affected Version< 1.53
CVSS6.5Medium
CVECVE-2018-11244
View all BBE vulnerabilities

Vulnerability Overview

The BBE theme before 1.53 for WordPress allows a direct launch of an HTML editor.

Technical Analysis

REMEDIATION: Update to version 1.53, or a newer patched version --- IDENTIFIER: CWE-862 (Missing Authorization) The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C