CVE-2023-25447 – WordPress ColorWay Theme <= 4.2.3 is vulnerable to Cross Site Request Forgery (CSRF)
https://notcve.org/view.php?id=CVE-2023-25447
Cross-Site Request Forgery (CSRF) vulnerability in Inkthemescom ColorWay theme <= 4.2.3 versions. The ColorWay Theme for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.2.3. This is due to missing or incorrect nonce validation on an unknown function. This makes it possible for unauthenticated attackers to perform an unknown action granted they can trick a site administrator into performing an action such as clicking on a link. The impact of this vulnerability is unknown. • https://patchstack.com/database/vulnerability/colorway/wordpress-colorway-theme-4-2-3-csrf-leading-to-arbitrary-plugin-activation?_s_id=cve • CWE-352: Cross-Site Request Forgery (CSRF) •
CVE-2022-3750 – Ask Me < 6.8.7 - Post Deletion via CSRF
https://notcve.org/view.php?id=CVE-2022-3750
The has a CSRF vulnerability that allows the deletion of a post without using a nonce or prompting for confirmation. Tiene una vulnerabilidad CSRF que permite eliminar una publicación sin utilizar un nonce ni solicitar confirmación. The Ask Me theme for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, but not including, 6.8.7. This is due to missing or incorrect nonce validation on one of its functions. This makes it possible for unauthenticated attackers to invoke that function, via forged request granted they can trick a site administrator into performing an action such as clicking on a link. • https://wpscan.com/vulnerability/5019db80-0356-497d-b488-a26a5de78676 • CWE-352: Cross-Site Request Forgery (CSRF) •
CVE-2022-1251 – Ask Me < 6.8.4 - CSRF in Edit Profile
https://notcve.org/view.php?id=CVE-2022-1251
The Ask me WordPress theme before 6.8.4 does not perform nonce checks when processing POST requests to the Edit Profile page, allowing an attacker to trick a user to change their profile information by sending a crafted request. El tema Ask me de WordPress versiones anteriores a 6.8.4, no lleva a cabo comprobaciones de nonce cuando procesa peticiones POST a la página Edit Profile, lo que permite a un atacante engañar a un usuario para que cambie su información de perfil mediante el envío de una petición diseñada. The Ask Me theme for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 6.8.3. This is due to missing or incorrect nonce validation when editing profiles. This makes it possible for unauthenticated attackers to edit user profiles, via forged request granted they can trick a site administrator into performing an action such as clicking on a link. • https://wpscan.com/vulnerability/34b3fc35-381a-4bd7-87e3-f1ef0a15a349 • CWE-352: Cross-Site Request Forgery (CSRF) •
CVE-2016-10961 – ColorWay <= 3.4.1 - Cross-Site Scripting
https://notcve.org/view.php?id=CVE-2016-10961
The colorway theme before 3.4.2 for WordPress has XSS via the contactName parameter. El tema colorway versiones anteriores a 3.4.2 para WordPress, presenta una vulnerabilidad de tipo XSS por medio del parámetro contactName. • https://sumofpwn.nl/advisory/2016/cross_site_scripting_vulnerability_in_colorway_wordpress_theme.html https://wpvulndb.com/vulnerabilities/8568 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •