Unauthenticated Settings Change Vulnerability in MULTIDOTS WooCommerce Plugin
CVE-2018-11579
5.3MEDIUM
Key Information:
- Vendor
Wordpress
- Vendor
- CVE Published:
- 31 May 2018
What is CVE-2018-11579?
The MULTIDOTS WooCommerce Category Banner Management plugin version 1.1.0 contains a vulnerability in its class-woo-banner-management.php file. This flaw allows for unauthenticated users to alter plugin settings via the wp_ajax_nopriv_ endpoint by sending requests with the wbm_save_shop_page_banner_data action. This exploitation could lead to unauthorized modifications and potential misuse of the plugin's functionalities, emphasizing the need for immediate security measures and awareness around plugin configurations.