CVE · Medium

CVE-2015-9456 — Child Theme Creator by Orbisius [orbisius-child-theme-creator] < 1.2.8

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2015-9456 Child Theme Creator by Orbisius [orbisius-child-theme-creator] < 1.2.8 Incorrect Permission Assignment for Critical Resource Medium 6.5 < 1.2.8 1.2.8 2015-07-08

CVE-2015-9456

The Orbisius Child Theme Creator plugin before version 1.2.8 contains an access control vulnerability that allows unauthorized modification of files through the wp-admin/admin-ajax.php endpoint. An attacker can exploit this flaw by manipulating the theme_1, theme_1_file, or theme_1_file_contents parameters in requests to the orbisius_ctc_theme_editor_ajax action with the save_file sub-command. This vulnerability enables unauthenticated users to alter theme files without proper permission checks.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.