Mesmerize <= 1.6.89 & Materialis <= 1.0.172 - Authenticated Arbitrary Options Update

2019-12-02 00:00
Jerome Bruandet

Strategic Overview

Status
Patched in 1.6.90
Affected ThemeMesmerize
Affected Version<= 1.6.89
CVSS8.8High
CVECVE-2019-25142
View all Mesmerize vulnerabilities

Vulnerability Overview

The Mesmerize & Materialis themes for WordPress are vulnerable to authenticated options change in versions up to, and including,1.6.89 (Mesmerize) and 1.0.172 (Materialis). This is due to 'companion_disable_popup' function only checking the nonce while sending user input to the 'update_option' function. This makes it possible for authenticated attackers to change otherwise restricted options.

Technical Analysis

REMEDIATION: Update to version 1.6.90, or a newer patched version --- IDENTIFIER: CWE-862 (Missing Authorization) The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C