Vulnerability Description
The basic_settings function in the download manager plugin for WordPress before 2.7.3 allows remote authenticated users to update every WordPress option.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| W3Eden | Download Manager | < 2.7.3 |
References
- http://packetstormsecurity.com/files/130690/WordPress-Download-Manager-2.7.2-PriExploitThird Party AdvisoryVDB Entry
- http://packetstormsecurity.com/files/130690/WordPress-Download-Manager-2.7.2-PriExploitThird Party AdvisoryVDB Entry
FAQ
What is CVE-2014-9260?
CVE-2014-9260 is a vulnerability with a CVSS score of 8.8 (HIGH). The basic_settings function in the download manager plugin for WordPress before 2.7.3 allows remote authenticated users to update every WordPress option.
How severe is CVE-2014-9260?
CVE-2014-9260 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2014-9260?
Check the references section above for vendor advisories and patch information. Affected products include: W3Eden Download Manager.