WordPress Brands for WooCommerce plugin <= 3.8.2.2 - Broken Access Control vulnerability
CVE-2023-44149
5.3MEDIUM
What is CVE-2023-44149?
The missing authorization vulnerability in BeRocket's Brands for WooCommerce plugin allows attackers to exploit incorrectly configured access control security levels. This flaw has been identified in versions of the plugin prior to 3.8.2.2, potentially enabling unauthorized access to sensitive operations and functions. It is crucial for users of this plugin to review their configurations and apply necessary updates to mitigate the risks associated with this vulnerability.
Affected Version(s)
Brands for WooCommerce <= 3.8.2.2