vendor:
Clockstone WordPress Theme & Various CMSMasters Themes
by:
DigiP
7,5
CVSS
HIGH
File Upload Vulnerability
264
CWE
Product Name: Clockstone WordPress Theme & Various CMSMasters Themes
Affected Version From: 1.2 and lower
Affected Version To: 1.2 and lower
Patch Exists: YES
Related CWE: N/A
CPE: a:cmsmasters:clockstone
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2012
Clockstone and Various other CMSMasters Theme File Upload Vulnerabilities
A file upload vulnerability was discovered in Clockstone WordPress Theme & Various CMSMasters Themes, which allowed anyone to access a victim's site, by uploading whatever files they wanted to the site. The code that allowed this attack to happen, was in several files which did not require user authentication from logged in WordPress users, and anyone visiting the url directly would be able to execute the script directly.
Mitigation:
Users should remove the Clockstone WordPress Theme & Various CMSMasters Themes from their sites until CMSMasters had a chance to patch their theme(s).