Access violation vulnerability in ZoxPress – The All-In-One WordPress News Theme 2.12.0

The ZoxPress WordPress theme has a security issue that allows unauthorized changes to be made to the site, potentially giving attackers more privileges. This is because the theme does not have a check in place for the ‘backup_options’ function, which means that users with Subscriber-level access or higher can update any options on the site. This can be used by attackers to change the default role for new users to administrator, giving them full control over the site.

Detected in:

ZoxPress - The All-In-One WordPress News Theme fixed vulnerable versions: >= * <= 2.12.0

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.