Medium 6.5 Unfixed Closed
2022-04-18≤ 1.2.8
CVE-2022-23975
CVE-2022-23975
AccessPress Themes and Plugin <= Various Versions - Cross-Site Request Forgery
WordPress Ultra Seven theme <= 1.2.8 - Arbitrary File Upload vulnerability
WordPress Ultra Seven theme <= 1.2.8 - Cross-Site Request Forgery (CSRF) leading to Arbitrary Plugin Activation/Deactivation
WordPress Ultra Seven theme <= 1.2.8 - Authenticated Arbitrary Plugin Activation/Deactivation vulnerability