HomeSecurityWordPress' Elegant Themes fixes dangerous vulnerabilities

WordPress' Elegant Themes patches dangerous vulnerabilities

Elegant Themes, a company that provides themes and plugins for WordPress, has issued a security warning about two of its themes and three plugins that allow attackers to change website content or plugin settings.

An anonymous security researcher discovered the issues and privately disclosed the problem to Elegant Themes. The company worked with the security researcher and a private web security vendor (Sucuri) to assess and address the issues.

WordPress' Elegant Themes patches dangerous vulnerabilities

Once the company managed to patch all the vulnerabilities reported, it began sending emails to all its customers—the first one was sent on February 17th, and then resent it a few days later. You can read a copy of the letter here, courtesy of SC Magazine.

The vulnerabilities affected the Divi, Divi 2.3 (legacy) and Extra themes and the Divi Builder, Bloom and Monarch plugins.

According to Nick Roach from Elegant Themes, the Divi Builder plugin included an information-disclosing bug that could be exploited to change the privileges of a lower-level user so that they could modify the content of the site.

Because the Divi Builder plugin is included by default in Divi, Divi 2.3 (legacy), and Extra themes, all sites built on these themes and that have user registration open are vulnerable to attacks.

A second, similar, vulnerability was found in the Bloom and Monarch plugins that allowed users with minimal privileges to modify the settings of these plugins.

The company has provided patches and new versions of the plugins to fix all the issues discovered. Users are advised to upgrade their site as soon as possible, but for users who are unable to upgrade, the patches will fix all the issues without creating compatibility issues during the update.

All these updates and patches will be provided free of charge, even for older customers who no longer have an active subscription.

Elegant Themes says that the following plugins and versions of these themes have all had their issues fixed: Divi theme 2.6.4, Divi (legacy) theme 2.3.4, Extra theme 1.2.4, Divi Builder plugin 1.2.4, Bloom plugin 1.1.1, and Monarch plugin 1.2.7.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS