Easy Theme Options WordPress Plugin Missing Authorization Vulnerability Allowing Arbitrary Settings Import
Vulnerability
A vulnerability exists in the Easy Theme Options plugin for WordPress, in all versions through 1.0, due to missing authorization checks in the 'eto_import_settings' function. This flaw allows authenticated attackers with Subscriber-level access and above to import arbitrary plugin settings using the 'eto_import_settings' parameter.
Impact
Exploitation of this vulnerability could lead to unauthorized importation of plugin settings, potentially allowing attackers to manipulate the site's theme options or other related configurations.
Added: Dec 13, 2025, 5:38 PM
Updated: Dec 13, 2025, 5:38 PM
Vulnerability Rating
Custom Algorithm
spread
0.0impact
0.6exploitability
5.9remediation
0.0relevance
1.5threat
3.2urgency
2.9incentive
1.7Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
