Vulnerability Description
The stops-core-theme-and-plugin-updates plugin before 8.0.5 for WordPress has insufficient restrictions on option changes (such as disabling unattended theme updates) because of a nonce check error.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Easyupdatesmanager | Easy Updates Manager | < 8.0.5 |
References
- https://wordpress.org/plugins/stops-core-theme-and-plugin-updates/#developersRelease Notes
- https://wpvulndb.com/vulnerabilities/9837Third Party Advisory
- https://wordpress.org/plugins/stops-core-theme-and-plugin-updates/#developersRelease Notes
- https://wpvulndb.com/vulnerabilities/9837Third Party Advisory
FAQ
What is CVE-2019-15650?
CVE-2019-15650 is a vulnerability with a CVSS score of 4.3 (MEDIUM). The stops-core-theme-and-plugin-updates plugin before 8.0.5 for WordPress has insufficient restrictions on option changes (such as disabling unattended theme updates) because of a nonce check error.
How severe is CVE-2019-15650?
CVE-2019-15650 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-15650?
Check the references section above for vendor advisories and patch information. Affected products include: Easyupdatesmanager Easy Updates Manager.