Unauthorized Data Modification Vulnerability in WooCommerce Wishlist plugin
CVE-2024-10567
7.5HIGH
What is CVE-2024-10567?
The TI WooCommerce Wishlist plugin for WordPress is susceptible to unauthorized data modification due to an absence of a necessary capability check in the 'wizard' function. This vulnerability affects all versions up to and including version 2.9.1. Attackers can exploit this flaw to create new pages, modify settings of the plugin, and execute limited updates without authentication, posing significant risks to the integrity and security of the website utilizing this plugin.