vendor:
Archin
by:
bwall
7,5
CVSS
HIGH
Unauthenticated Configuration Access
284
CWE
Product Name: Archin
Affected Version From: 3.2
Affected Version To: 3.2
Patch Exists: YES
Related CWE: N/A
CPE: a:wptitans:archin
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Ubuntu
2012
Archin WordPress Theme Unauthenticated Configuration Access
This exploit allows an attacker to change the configuration of the Archin WordPress Theme without authentication. The attacker can change the admin email, enable user registration, and set the default role to administrator. This allows the attacker to register a new user with administrator privileges.
Mitigation:
Ensure that all WordPress themes are up to date and that all users have strong passwords.