CVE-2020-28649

Severity CVSS v4.0:
Pending analysis
Type:
CWE-352 Cross-Site Request Forgery (CSRF)
Publication date:
16/11/2020
Last modified:
27/11/2020

Description

The orbisius-child-theme-creator plugin before 1.5.2 for WordPress allows CSRF via orbisius_ctc_theme_editor_manage_file.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:orbisius:child_theme_creator:*:*:*:*:*:wordpress:*:* 1.5.2 (excluding)