Site5 Various Affected Themes (Various Versions) - Email Spoofing

2012-07-15 00:00
xxDigiPxx

Strategic Overview

Status
Patched in 2.0
Affected Themeboldy
Affected Version< 2.0
CVSS5.3Medium
CVEN/A
View all boldy vulnerabilities

Vulnerability Overview

Various Site5 themes for WordPress are vulnerable to Email Spoofing. This makes it possible for unauthenticated attackers to modify email addresses to potentially perform future attacks on other users.

Technical Analysis

REMEDIATION: Update to version 2.0, or a newer patched version --- IDENTIFIER: CWE-345 (Insufficient Verification of Data Authenticity) The product does not sufficiently verify the origin or authenticity of data, in a way that causes it to accept invalid data.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C