WordPress security changelog
HIGH
CVE-2014-7297
Modified
Enfold: A security weakness
Enfold is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
CVE / CNA score
10.0
CVSS · cve@mitre.org
NVD score
10.0
CVSS 2.0 · nvd@nist.gov
- Component
- Enfold
- Plugin slug
enfold- Affected
- See vendor advisory
- Safe version
- See mitigation notes
- Published
- Oct 13, 2014
- Weakness
- NVD-CWE-noinfo
This CVE was published Oct 13, 2014 and is one of 10 known issues for this theme.
What to do
Patch or disable the affected component.
Update Enfold to a release outside the affected range, or disable and remove it until a fixed version is available.
Source record
Technical description
Unspecified vulnerability in the folder framework in the Enfold theme before 3.0.1 for WordPress has unknown impact and attack vectors.
NVD vector: AV:N/AC:L/Au:N/C:C/I:C/A:C
References