Unauthorized Data Modification Vulnerability in WooCommerce Wishlist plugin
CVE-2024-10567
7.5HIGH
Summary
The TI WooCommerce Wishlist plugin for WordPress is susceptible to unauthorized data modification due to an absence of a necessary capability check in the 'wizard' function. This vulnerability affects all versions up to and including version 2.9.1. Attackers can exploit this flaw to create new pages, modify settings of the plugin, and execute limited updates without authentication, posing significant risks to the integrity and security of the website utilizing this plugin.
References
CVSS V3.1
Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published