Easy Theme Options WordPress Plugin Missing Authorization Vulnerability Allowing Arbitrary Settings Import

Vulnerability

A vulnerability exists in the Easy Theme Options plugin for WordPress, in all versions through 1.0, due to missing authorization checks in the 'eto_import_settings' function. This flaw allows authenticated attackers with Subscriber-level access and above to import arbitrary plugin settings using the 'eto_import_settings' parameter.

Impact

Exploitation of this vulnerability could lead to unauthorized importation of plugin settings, potentially allowing attackers to manipulate the site's theme options or other related configurations.

Added: Dec 13, 2025, 5:38 PM
Updated: Dec 13, 2025, 5:38 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
0.6
exploitability
5.9
remediation
0.0
relevance
1.5
threat
3.2
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.