Unauthenticated Settings Change Vulnerability in MULTIDOTS WooCommerce Plugin
CVE-2018-11579

5.3MEDIUM

Key Information:

Vendor
Wordpress
Vendor
CVE Published:
31 May 2018

Summary

The MULTIDOTS WooCommerce Category Banner Management plugin version 1.1.0 contains a vulnerability in its class-woo-banner-management.php file. This flaw allows for unauthenticated users to alter plugin settings via the wp_ajax_nopriv_ endpoint by sending requests with the wbm_save_shop_page_banner_data action. This exploitation could lead to unauthorized modifications and potential misuse of the plugin's functionalities, emphasizing the need for immediate security measures and awareness around plugin configurations.

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability Reserved

  • Vulnerability published

.