HomeDefault status
unaffected
Any version before 1.6.8
affected
Description
The Construction Light WordPress theme before 1.6.8 does not have authorisation and CSRF when activating via an AJAX action, allowing any authenticated users, such as subscriber to activate arbitrary .
Problem types
CWE-287 Improper Authentication
CWE-352 Cross-Site Request Forgery (CSRF)
Product status
Any version before 1.6.8
Credits
Khaled Alenazi (Nxploited)
WPScan
References
wpscan.com/...rability/cfabf8b2-30a4-462f-996c-79888a439c09/
Data based on CVE®. Copyright © 1999-2025, The MITRE Corporation. All rights reserved.