Custom Product Tabs for WooCommerce <= 1.7.7 - Subscriber+ Settings Update

2022-06-28 00:00
Tien Nguyen Ahn

Strategic Overview

Status
Patched in 1.7.8
Affected Version<= 1.7.7
CVSS6.3Medium
CVECVE-2022-28666
View all Custom Product Tabs for WooCommerce vulnerabilities

Vulnerability Overview

The WordPress plugin Custom Product Tabs for WooCommerce is vulnerable to unauthenticated options update due to lack of authorization in the register_rest_route function in versions up to, and including 1.7.7. This allows an attacker to change the plugin's options.

Technical Analysis

REMEDIATION: Update to version 1.7.8, or a newer patched version --- IDENTIFIER: CWE-862 (Missing Authorization) The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C