Woocommerce Category Banner Management <= 1.1.0 - Missing Authorization

2018-05-29 00:00
Jack K.

Strategic Overview

Status
Patched in 1.1.1
Affected Version<= 1.1.0
CVSS6.5Medium
CVECVE-2018-11579
View all Banner Management For WooCommerce vulnerabilities

Vulnerability Overview

class-woo-banner-management.php in the MULTIDOTS WooCommerce Category Banner Management plugin 1.1.0 for WordPress has an Unauthenticated Settings Change Vulnerability, related to certain wp_ajax_nopriv_ usage. Anyone can change the plugin's setting by simply sending a request with a wbm_save_shop_page_banner_data action.

Technical Analysis

REMEDIATION: Update to version 1.1.1, or a newer patched version --- IDENTIFIER: CWE-862 (Missing Authorization) The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C