CVE-2019-15650
Description
The stops-core-theme-and-plugin-updates plugin before 8.0.5 for WordPress has insufficient restrictions on option changes (such as disabling unattended theme updates) because of a nonce check error.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
A nonce check error in Easy Updates Manager before 8.0.5 allows attackers to change plugin options, such as disabling updates.
Vulnerability
The Easy Updates Manager plugin (stops-core-theme-and-plugin-updates) before version 8.0.5 for WordPress contains a nonce check error that leads to insufficient restrictions on option changes [1]. This flaw allows an attacker to modify plugin settings, such as disabling unattended theme updates, without proper authorization. The vulnerability affects all versions prior to 8.0.5.
Exploitation
An attacker can exploit this vulnerability by sending a crafted HTTP request to the WordPress site. The nonce validation is flawed, so the attacker can bypass the intended security check and alter plugin options. No authentication is required; the attacker only needs network access to the site. The request includes the desired option changes and a manipulated nonce value.
Impact
Successful exploitation allows the attacker to change critical plugin settings, including disabling automatic updates for themes, plugins, or WordPress core. This can leave the site vulnerable to known exploits that would otherwise be patched by updates. The attacker gains the ability to control update behavior, potentially increasing the risk of compromise.
Mitigation
The vulnerability is fixed in version 8.0.5 of the Easy Updates Manager plugin [1]. Users should update to this version or later immediately. If updating is not possible, consider temporarily deactivating the plugin until a patch can be applied. No other workarounds are documented.
AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2- WordPress/stops-core-theme-and-plugin-updates plugindescription
- Range: <8.0.5
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- wordpress.org/plugins/stops-core-theme-and-plugin-updates/mitrex_refsource_MISC
- wpvulndb.com/vulnerabilities/9837mitrex_refsource_MISC
News mentions
0No linked articles in our index yet.