vendor:
Colormix Theme
by:
SecurityFocus
7,5
CVSS
HIGH
Cross-site Scripting, Path-disclosure, Content-spoofing
79, 200, 20
CWE
Product Name: Colormix Theme
Affected Version From: N/A
Affected Version To: N/A
Patch Exists: YES
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2012
Colormix Theme for WordPress Multiple Vulnerabilities
The Colormix theme for WordPress is prone to multiple security vulnerabilities, including cross-site scripting, path-disclosure, and multiple content-spoofing vulnerabilities. An attacker may leverage these issues to obtain potentially sensitive information and to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and to control how the site is rendered to the user; other attacks are also possible.
Mitigation:
Users should apply the latest security patches to the affected application to mitigate the risk of exploitation.