CVE-2019-25142




The Mesmerize & Materialis themes for WordPress are vulnerable to authenticated options change in versions up to, and including,1.6.89 (Mesmerize) and 1.0.172 (Materialis). This is due to 'companion_disable_popup' function only checking the nonce while sending user input to the 'update_option' function. This makes it possible for authenticated attackers to change otherwise restricted options.



We have discovered 168 live websites that are affected by CVE-2019-25142.

Contact us to get more info




Affected Software

Product  Mesmerize
Category Wordpress Themes
Vulnerable Versions
  • from 0 through 1.6.89
Total Vulnerable Versions54
Vulnerable Domains168 live websites (23.33% of Mesmerize install base)


Distribution by Website Rank

The diagram provides a graphic representation of the correlation between the occurrence of CVE-2019-25142 and the relative popularity of websites


Details

  • Published - Jun 7, 2023
  • Updated - Jun 7, 2023

Credits

  • Jerome Bruandet (finder)




Countries

United States35 websites



Germany33 websites
GB12 websites
Italy10 websites
France9 websites
Poland9 websites
Russia8 websites
Denmark6 websites
Spain6 websites
Brazil4 websites

TLDs

.com49 websites
.de24 websites
.org16 websites
.pl6 websites
.it6 websites
.net5 websites
.co.uk5 websites
.ru5 websites
.dk5 websites
.eu4 websites

Vulnerable Versions

Vulnerable versions are highlighted in red


Geographical Distribution

The distribution of websites across the globe that are exposed to CVE-2019-25142 through included software libraries and plugins.



References


Websites affected by CVE-2019-25142

Top websites that are affected by CVE-2019-25142. Please click on the "Contact us" button above to get more information.
DomainCountryRankContacts
*******************.de Germany**,***
******.info Russia***,***
**********.com United States***,***
***************.org United States***,***
***********.com United States***,***
***.************.de Germany***,***
***********.com United States***,***
***.********************.de Germany***,***
***.md Moldova***,***
****************.com GB***,***
See full domain list