WordPress Plugin Vulnerabilities

Multiple WooCommerce Add-Ons - Low Priv Arbitrary Blog Options Update/Access/Deletion & Plugin's Settings Update/Export/Import

Description

The svx_ajax_factory AJAX action of the plugins, available to authenticated users, do not have CSRF and capability checks, which could allow any authenticated user, such as subscriber to change/view/delete arbitrary WordPress options, retrieve the list of users, import/export/update the plugins' settings.

Affects Plugins

References

Classification

Type
ACCESS CONTROLS
CWE
CVSS

Miscellaneous

Original Researcher
Jerome Bruandet (nintechnet)
Verified
No

Timeline

Publicly Published
2021-09-20 (about 4 years ago)
Added
2021-09-20 (about 4 years ago)
Last Updated
2023-06-08 (about 2 years ago)

Other