Themes Vulnerabilities

Construction Light < 1.6.8 - Subscriber+ Arbitrary Plugin Activation

Description

The theme does not have authorisation and CSRF when activating plugins via an AJAX action, allowing any authenticated users, such as subscriber to activate arbitrary plugins.

Proof of Concept

Affects Themes

Fixed in 1.6.8

References

Classification

Miscellaneous

Original Researcher
Khaled Alenazi (Nxploited)
Submitter
Khaled Alenazi (Nxploited)
Verified
Yes

Timeline

Publicly Published
2025-11-21 (about 1 month ago)
Added
2025-11-21 (about 1 month ago)
Last Updated
2025-11-21 (about 1 month ago)

Other