Swape Theme - Authentication Bypass and Stored XSS
Similar to https://wpvulndb.com/vulnerabilities/8061, but with no authentication The theme suffers from a privilege escalation vulnerability, any user can trigger this vulnerability due to weak permissions checking. An attacker can update options, such as changing user's default role, registration state and others, which may lead to executing commands/code on the server and taking over the website.
|Proof of Concept||
fixed in version 1.2.1
|Publicly Published||2018-02-08 (over 1 year ago)|
|Added||2018-02-09 (over 1 year ago)|
|Last Updated||2019-06-03 (about 2 months ago)|