CVE-2012-0934: Code Injection
Published Jan 29, 2012
·Updated
PHP remote file inclusion vulnerability in ajax/savetag.php in the Theme Tuner plugin for WordPress before 0.8 allows remote attackers to execute arbitrary PHP code via a URL in the tt-abspath parameter.
Affected Software
7 affected components
Zingiri Theme Tuner Plugin<=0.7
Zingiri Theme Tuner Plugin=0.1
Zingiri Theme Tuner Plugin=0.2
Zingiri Theme Tuner Plugin=0.3
Zingiri Theme Tuner Plugin=0.4
Zingiri Theme Tuner Plugin=0.6
WordPress
Remediation
Patch Available
Event History
Jan 29, 2012
CVE Published
via MITRE·02:00 AM
Data Sourced
via MITRE·02:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2012-0934?
CVE-2012-0934 is considered a high severity vulnerability due to its potential for remote code execution.
2
How do I fix CVE-2012-0934?
To fix CVE-2012-0934, update the Theme Tuner plugin for WordPress to version 0.8 or later.
3
What types of attacks exploit CVE-2012-0934?
CVE-2012-0934 can be exploited through remote file inclusion attacks that execute arbitrary PHP code on the server.
4
Which versions of the Theme Tuner plugin are affected by CVE-2012-0934?
CVE-2012-0934 affects all versions of the Theme Tuner plugin prior to 0.8.
5
Is my WordPress installation safe if I am using a non-vulnerable plugin version?
Yes, if you are using a version of the Theme Tuner plugin that is 0.8 or later, your WordPress installation is not affected by CVE-2012-0934.