CVE-2014-9735
Summary
| CVE | CVE-2014-9735 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2015-06-30 14:59:03 UTC |
| Updated | 2026-05-06 22:30:45 UTC |
| Description | The ThemePunch Slider Revolution (revslider) plugin before 3.0.96 for WordPress and Showbiz Pro plugin 1.7.1 and earlier for Wordpress does not properly restrict access to administrator AJAX functionality, which allows remote attackers to (1) upload and execute arbitrary files via an update_plugin action; (2) delete arbitrary sliders via a delete_slider action; and (3) create, (4) update, (5) import, or (6) export arbitrary sliders via unspecified vectors. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
PartialIntegrity
PartialAvailability
PartialAV:N/AC:L/Au:N/C:P/I:P/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Themepunch | Showbiz Pro | All | All | All | All |
| Application | Themepunch | Slider Revolution | All | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| RevSlider Vulnerability Leads To Massive WordPress SoakSoak Compromise | Sucuri Blog | af854a3a-2127-422b-91ae-364da2661108 | blog.sucuri.net | Exploit |
| Slider Revolution Responsive/Showbiz Pro Responsive Teaser Multiple Security Bypass Vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| 403 Forbidden | af854a3a-2127-422b-91ae-364da2661108 | plugins.trac.wordpress.org | |
| Another Revslider Vulnerability | What is Going On? | af854a3a-2127-422b-91ae-364da2661108 | whatisgon.wordpress.com | Exploit |
| Full Disclosure: Slider Revolution/Showbiz Pro shell upload exploit | af854a3a-2127-422b-91ae-364da2661108 | seclists.org | Exploit |
| WordPress Slider Revolution Shell Upload | af854a3a-2127-422b-91ae-364da2661108 | wpvulndb.com | |
| Old Revolution Slider Pre 4.2 Vulnerabilty Explained | af854a3a-2127-422b-91ae-364da2661108 | www.themepunch.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.