Swape - App Showcase & App Store WordPress Theme < 1.2.1 - Missing Authorization to Arbitrary Options Update

2018-02-08 00:00
Aaron Bernstein

Strategic Overview

Status
Patched in 1.2.1
Affected Version< 1.2.1
CVSS9.8Critical
CVECVE-2018-21013
View all Swape - App Showcase & App Store WordPress Theme vulnerabilities

Vulnerability Overview

The "Swape - App Showcase & App Store WordPress Theme" theme for WordPress is vulnerable to authorization bypass due to a missing capability check on the 'call_upper_load_settings' AJAX action in versions up to 1.2.1. This makes it possible for unauthenticated attackers to modify arbitrary site options which can be used to create new administrative user accounts and achieve privilege escalation.

Technical Analysis

REMEDIATION: Update to version 1.2.1, or a newer patched version --- IDENTIFIER: CWE-862 (Missing Authorization) The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C