Description
The Th Shop Mania theme for WordPress is vulnerable to unauthorized arbitrary plugin installation due to a missing capability check on the th_shop_mania_install_and_activate_callback() function in all versions up to, and including, 1.4.9. This makes it possible for authenticated attackers, with Subscriber-level access and above, to install arbitrary plugins which can be leveraged to exploit other vulnerabilities and achieve remote code execution and privilege escalation.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
History
Tue, 12 Nov 2024 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Themehunk
Themehunk th Shop Mania |
|
| CPEs | cpe:2.3:a:themehunk:th_shop_mania:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Themehunk
Themehunk th Shop Mania |
|
| Metrics |
ssvc
|
Sat, 09 Nov 2024 03:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Th Shop Mania theme for WordPress is vulnerable to unauthorized arbitrary plugin installation due to a missing capability check on the th_shop_mania_install_and_activate_callback() function in all versions up to, and including, 1.4.9. This makes it possible for authenticated attackers, with Subscriber-level access and above, to install arbitrary plugins which can be leveraged to exploit other vulnerabilities and achieve remote code execution and privilege escalation. | |
| Title | Th Shop Mania <= 1.4.9 - Authenticated (Subscriber+) Arbitrary Plugin Installation/Activation | |
| Weaknesses | CWE-862 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2026-04-08T17:17:40.499Z
Reserved: 2024-11-01T11:08:04.631Z
Link: CVE-2024-10674
Updated: 2024-11-12T18:43:04.650Z
Status : Deferred
Published: 2024-11-09T04:15:04.677
Modified: 2026-04-15T00:35:42.020
Link: CVE-2024-10674
No data.
OpenCVE Enrichment
No data.
Weaknesses