CVE Vulnerabilities

CVE-2016-10972

Improper Privilege Management

Published: Sep 16, 2019 | Modified: Sep 16, 2019
CVSS 3.x
9.8
CRITICAL
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

The newspaper theme before 6.7.2 for WordPress has a lack of options access control via td_ajax_update_panel.

Weakness

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

Affected Software

Name Vendor Start Version End Version
Newspaper Tagdiv * 6.7.2 (excluding)

Potential Mitigations

References