WORDFENCE-9b8b5363-2450-42b5-8295-78ced3682b14
high
📛 Threat Title
RokStories <= 1.25 - Abuse of Functionality
Description
The WordPress RokStories plugin is vulnerable to Abuse of Functionality via the 'src' parameter in the 'thumb.php' file in versions up to, and including, 1.25. This makes it possible for unauthenticated attackers to use implemented functions for unintended/malicious reasons. Affected software — plugin: RokStories (affected: *-1.25). CVSS 7.3 (High) — CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L.
Indicators of Compromise (0)
No indicators of compromise on this threat.
References (2)
Remediations (1)
-
Wordfence remediation: RokStoriesWordfence
Update to version 1.26, or a newer patched version
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.