CVE-2019-6703
Description
Incorrect access control in migla_ajax_functions.php in the Calmar Webmedia Total Donations plugin through 2.0.5 for WordPress allows unauthenticated attackers to update arbitrary WordPress option values, leading to site takeover. These attackers can send requests to wp-admin/admin-ajax.php to call the miglaA_update_me action to change arbitrary options on affected sites. This can be used to enable new user registration and set the default role for new users to Administrator.
In plain language
AI Worth attentionCVE-2019-6703 is a WordPress plugin flaw (Calmar Webmedia “Total Donations” up to version 2.0.5) that lets outsiders change your site settings without logging in, so you should act if you use this plugin.
CVE-2019-6703 is an access-control failure in migla_ajax_functions.php in the Calmar Webmedia Total Donations plugin (through 2.0.5) that allows unauthenticated attackers to call an admin-ajax action (miglaA_update_me) to update arbitrary WordPress option values, enabling site takeover by changing user/role-related settings.
What to do now
- Check whether you run the WordPress plugin “Total Donations” and identify its version (especially if it’s 2.0.5 or older).
- If the plugin is installed and version is 2.0.5 or older, immediately disable the “Total Donations” plugin in WordPress.
- Look for any vendor update for “Total Donations” that addresses CVE-2019-6703; if you cannot find a fixed version, plan to remove the plugin and replace it with a safe alternative.
- Restrict or temporarily block access to WordPress’s admin-ajax.php from the internet at your firewall/WAF while you remediate.
- After changes, verify no new administrator accounts were created and review WordPress user roles and recent admin activity.
CVSS Vector Breakdown
AV:NAttack VectorAC:LAttack ComplexityPR:NPrivileges RequiredUI:NUser InteractionS:UScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Exploit details including PoC links, Metasploit modules, and scanner templates are available after registration.
View exploit detailsReferences
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2019-6703 and every CVE in our database. Create a free account — no credit card required.
Create Free Account