Swape - App Showcase & App Store WordPress Theme < 1.2.1 - Missing Authorization to Arbitrary Options Update
2018-02-08 00:00
Aaron BernsteinStrategic Overview
StatusPatched in 1.2.1
Affected ThemeSwape - App Showcase & App Store WordPress Theme
Affected Version
< 1.2.1CVSS9.8Critical
CVE
CVE-2018-21013Vulnerability Overview
The "Swape - App Showcase & App Store WordPress Theme" theme for WordPress is vulnerable to authorization bypass due to a missing capability check on the 'call_upper_load_settings' AJAX action in versions up to 1.2.1. This makes it possible for unauthenticated attackers to modify arbitrary site options which can be used to create new administrative user accounts and achieve privilege escalation.
Technical Analysis
REMEDIATION: Update to version 1.2.1, or a newer patched version --- IDENTIFIER: CWE-862 (Missing Authorization) The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
External References
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C