CVE-2014-9735
Summary
| CVE | CVE-2014-9735 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2015-06-30 14:59:00 UTC |
| Updated | 2016-11-28 19:14:00 UTC |
| Description | The ThemePunch Slider Revolution (revslider) plugin before 3.0.96 for WordPress and Showbiz Pro plugin 1.7.1 and earlier for Wordpress does not properly restrict access to administrator AJAX functionality, which allows remote attackers to (1) upload and execute arbitrary files via an update_plugin action; (2) delete arbitrary sliders via a delete_slider action; and (3) create, (4) update, (5) import, or (6) export arbitrary sliders via unspecified vectors. |
Risk And Classification
Problem Types: CWE-264
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Themepunch | Showbiz Pro | All | All | All | All |
| Application | Themepunch | Slider Revolution | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Slider Revolution Responsive/Showbiz Pro Responsive Teaser Multiple Security Bypass Vulnerabilities | BID | www.securityfocus.com | |
| Old Revolution Slider Pre 4.2 Vulnerabilty Explained | CONFIRM | www.themepunch.com | Vendor Advisory |
| RevSlider Vulnerability Leads To Massive WordPress SoakSoak Compromise | Sucuri Blog | MISC | blog.sucuri.net | Exploit |
| WordPress Slider Revolution Shell Upload | MISC | wpvulndb.com | |
| Full Disclosure: Slider Revolution/Showbiz Pro shell upload exploit | FULLDISC | seclists.org | Exploit |
| Another Revslider Vulnerability | What is Going On? | MISC | whatisgon.wordpress.com | Exploit |
| 403 Forbidden | MISC | plugins.trac.wordpress.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.