User Email Verification for WooCommerce <= 3.3.0 - Unauthenticated Arbitrary Options Update
2019-05-22 00:00
Brad GriffinStrategic Overview
StatusPatched in 3.4.0
Affected PluginUser Email Verification for WooCommerce
Affected Version
<= 3.3.0CVSS8.8High
CVE
N/AVulnerability Overview
The User Email Verification for WooCommerce plugin for WordPress is vulnerable to authorization bypass in versions up to, and including, 3.3.0. This is due to missing authorization checks on the save_tab_settings() function. This makes it possible for unauthenticated attackers to change otherwise restricted plugin options that can be used to inject new administrative user accounts.
Technical Analysis
REMEDIATION: Update to version 3.4.0, or a newer patched version --- IDENTIFIER: CWE-862 (Missing Authorization) The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
External References
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C