blog.nintechnet.com
https://blog.nintechnet.com/unauthenticated-stored-xss-vulnerability-in-wordpress-onetone-theme-unpatched CVE-2019-17230
MEDIUMNuclei
OneTone theme for WordPress includes/theme-functions.php Vulnerability
Record summary
CVE-2019-17230 has a selected CVSS score of 5.3 (medium); EIP currently links 1 Nuclei template.
Description
includes/theme-functions.php in the OneTone theme through 3.0.6 for WordPress allows unauthenticated options changes.
Description source: CVE List
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Apr 15, 2020 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Available material
- Nuclei templates
- 1
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
onetoneBrowse mageewp / onetone | VulnCheck | Version data not supplied | |
Nuclei templates
1ProjectDiscoveryMEDIUMWordPress OneTone theme <= 3.0.6 – Unauthenticated Options ChangesCVSS 5.3
includes/theme-functions.php in the OneTone theme through 3.0.6 for WordPress allows unauthenticated options changes.
Impact
Unauthenticated attackers can modify WordPress theme options, potentially changing site content like 404 page messages to inject malicious content or alter site behavior.
Remediation
Update the OneTone theme to version 3.0.7 or later, or switch to a different theme.
Authorsdaffainfo
Template tagscvecve2019wordpresswp-themewponetonevkevvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
CPE: cpe:2.3:a:mageewp:onetone:*:*:*:*:*:wordpress:*:*
https://blog.sucuri.net/2020/04/onetone-vulnerability-leads-to-javascript-cookie-hijacking.html https://blog.nintechnet.com/unauthenticated-stored-xss-vulnerability-in-wordpress-onetone-theme-unpatched/ https://nvd.nist.gov/vuln/detail/CVE-2019-17230
Source: ProjectDiscovery
References
2nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2019-17230