Executive brief
The Skyline WP theme for WordPress is vulnerable to a security flaw that could allow an attacker to trick an authorized user into performing unintended actions. By convincing a site administrator to click a malicious link or visit a specific webpage, an attacker could potentially modify site settings or configurations without the user's knowledge. This could lead to unauthorized changes to the website's appearance or functionality.
Technical details
A Cross-Site Request Forgery (CSRF) vulnerability exists in the Extend Themes Skyline WP theme for WordPress (versions up to and including 1.0.10). The vulnerability stems from a lack of proper nonce validation or similar CSRF protections within the theme's administrative functions. An unauthenticated remote attacker can exploit this by crafting a malicious request and tricking a logged-in administrator into executing it via social engineering (e.g., a malicious link). Successful exploitation allows the attacker to perform unauthorized actions with the privileges of the victim user, such as modifying theme settings. The issue is resolved in version 1.0.11.
Affected products
- Extend Themes Skyline WP n/a through 1.0.10
Timeline
- 2024-01-28: other: Vulnerability reported by researcher
- 2024-05-13: advisory: Patchstack advisory published
- 2026-06-17: disclosed: NVD publication date