Vulnerability Overview

The MWB Point of Sale (POS) for WooCommerce plugin for WordPress is vulnerable to authorization bypass in versions up to, and including, 1.0.0. This is due to missing nonce validation and capability checks on several AJAX actions found within the plugin . This makes it possible for authenticated attackers, with low-level privileges, such as subscriber, to execute otherwise restricted AJAX calls and modify the plugin's settings.

Technical Analysis

REMEDIATION: Update to version 1.0.1, or a newer patched version --- IDENTIFIER: CWE-862 (Missing Authorization) The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C