Themes Vulnerabilities

Swape Theme - Authentication Bypass and Stored XSS

Description

Similar to https://wpvulndb.com/vulnerabilities/8061, but with no authentication

The theme suffers from a privilege escalation vulnerability, any user can trigger this vulnerability due to weak permissions checking.

An attacker can update options, such as changing user's default role, registration state and others, which may lead to executing commands/code on the server and taking over the website.

Proof of Concept

Affects Themes

Fixed in 1.2.1

References

Miscellaneous

Submitter
Aaron
Submitter twitter
Verified
No

Timeline

Publicly Published
2018-02-08 (about 8 years ago)
Added
2018-02-09 (about 8 years ago)
Last Updated
2020-09-22 (about 5 years ago)

Other