
Inherited a WP site on an abandoned ThemeForest theme bundling Redux Framework from 2017. Used Opus to audit it: 5 critical findings incl CVE-2021-38314. Leaks some key hashes to any anonymous visitor. CC wrote a 175-line mu-plugin and now all 9 endpoints return 403. Amazing
Post summary
The post reports a critical CVE (2021‑38314) found in an abandoned WordPress theme and notes that a custom mu‑plugin was created to mitigate the flaw, preventing endpoint access. No exploitation or PoC details are included.
