Critical severity9.8NVD Advisory· Published Sep 9, 2019· Updated Jun 17, 2026
CVE-2018-21013
CVE-2018-21013
Description
The Swape theme before 1.2.1 for WordPress has incorrect access control, as demonstrated by allowing new administrator accounts via vectors involving xmlPath to wp-admin/admin-ajax.php.
Affected products
3- WordPress/Swape themedescription
Patches
Vulnerability mechanics
References
1- wpvulndb.com/vulnerabilities/9024nvdExploitProductRelease NotesThird Party Advisory
News mentions
0No linked articles in our index yet.