VYPR
Unrated severityNVD Advisory· Published Sep 9, 2019· Updated Aug 5, 2024

CVE-2018-21013

CVE-2018-21013

Description

The Swape theme before 1.2.1 for WordPress has incorrect access control, as demonstrated by allowing new administrator accounts via vectors involving xmlPath to wp-admin/admin-ajax.php.

Affected products

2
  • WordPress/Swape themedescription
  • WordPress/Swapellm-create
    Range: <1.2.1

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.