CVE-2020-28649: Orbisius Child Theme Creator

High severity, CVSS 8.8. EPSS: 0.8% chance of exploitation in the next 30 days.

The orbisius-child-theme-creator plugin before 1.5.2 for WordPress allows CSRF via orbisius_ctc_theme_editor_manage_file.

Affected products

  • Orbisius Child Theme Creator: before 1.5.2 (fixed in 1.5.2)

Published 2020-11-16. Last modified 2026-06-17.