漏洞描述
Newspaper Theme versions 6.4 to 6.7.1 for WordPress lacked proper options access control through td_ajax_update_panel, which led to a Privilege Escalation vulnerability.
id: CVE-2016-10972
info:
name: Newspaper Theme 6.4–6.7.1 - Privilege Escalation
author: pussycat0x
severity: critical
description: |
Newspaper Theme versions 6.4 to 6.7.1 for WordPress lacked proper options access control through td_ajax_update_panel, which led to a Privilege Escalation vulnerability.
reference:
- https://wpscan.com/vulnerability/5365ecca-93e2-4bfc-bd4a-6f61d7d75e96/
classification:
cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
cvss-score: 9.8
cve-id: CVE-2016-10972
cwe-id: CWE-269
epss-score: 0.66842
epss-percentile: 0.98472
cpe: cpe:2.3:a:tagdiv:newspaper:*:*:*:*:*:wordpress:*:*
metadata:
fofa-query: 'body="wp-content/themes/mTheme-Unus/"'
vendor: tagdiv
product: newspaper
framework: wordpress
tags: wpscan,cve,cve2016,wp,wordpress,wpscan,wp-theme,newspaper,passive,vkev,vuln
http:
- method: GET
path:
- "{{BaseURL}}/wp-content/themes/Newspaper/style.css"
matchers:
- type: dsl
dsl:
- "status_code == 200"
- "compare_versions(version, '>= 6.4', '<= 6.7.1')"
- "contains(body, 'Newspaper')"
condition: and
extractors:
- type: regex
part: body
group: 1
name: version
regex:
- 'Version: ([0-9.]+)'
internal: true
# digest: 4a0a00473045022100d4ddab1a97b61c7e6e61ef047718008e054246565900b0419394d8b35e12cfb702202b62529455241c34908172cb85923691b0d240246a8c260bba376805d78aad64:922c64590222798bb761d5b6d8e72950