CVE-2019-17230: Medium severity mageewp onetone vulnerability
Published Apr 3, 2020
·Updated
includes/theme-functions.php in the OneTone theme through 3.0.6 for WordPress allows unauthenticated options changes.
Affected Software
1 affected component
Mageewp Onetone Wordpress<=3.0.6
Event History
Apr 3, 2020
CVE Published
via MITRE·02:16 PM
Data Sourced
via MITRE·02:16 PM
Description
Frequently Asked Questions
1
Which deployments are exposed to this issue?
WordPress sites using the Mageewp OneTone theme through version 3.0.6 are affected. The issue is reachable over the network without authentication.
2
What level of access does an attacker need?
No account, credentials, or user interaction are required. An unauthenticated remote attacker can change options through the vulnerable theme functionality.
3
What is the practical impact?
The reported CVSS vector indicates an integrity impact only: an attacker can modify site options, but confidentiality and availability impacts are not identified in the provided data.