ThemeFuse / Unyson

A WordPress framework that facilitates the development of WP themes
http://unyson.io
922 stars 217 forks source link

vulnerability? #399

Closed itxp2008 closed 9 years ago

itxp2008 commented 9 years ago

Hi,

I've received a couple of visits from this referrer

http://sourcebox.io/6035455e4acf19612b71c4adf9c854a9/markdown

my site is http://icydiablog.com

I haven't tested the procedure and i don't know why my site is targeted with this eploit

Check the first link for details.

danyj commented 9 years ago

Confirmed , regular logged in user can execute this http://prntscr.com/6lxetp

this should be fixed asap.

danyj commented 9 years ago

This code should not run at all unless the option is in use. I don't have the option runnable enabled anywhere. add_action should be added only if option is enabled/used in a form and not automatically https://github.com/ThemeFuse/Unyson/blob/8a354fc97b5f6da7c52285b9a02bb8e1b9d45783/framework/includes/option-types/runnable/class-fw-option-type-runnable.php#L139