Unauthenticated Settings Change Vulnerability in MULTIDOTS WooCommerce Plugin
CVE-2018-11579
5.3MEDIUM
Key Information:
- Vendor
- Wordpress
- Vendor
- CVE Published:
- 31 May 2018
Summary
The MULTIDOTS WooCommerce Category Banner Management plugin version 1.1.0 contains a vulnerability in its class-woo-banner-management.php file. This flaw allows for unauthenticated users to alter plugin settings via the wp_ajax_nopriv_ endpoint by sending requests with the wbm_save_shop_page_banner_data action. This exploitation could lead to unauthorized modifications and potential misuse of the plugin's functionalities, emphasizing the need for immediate security measures and awareness around plugin configurations.
References
CVSS V3.1
Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability Reserved
Vulnerability published