WordPress Plugin Vulnerabilities

UPS Live Rates and Access Points < 3.0.0 - Missing Authorization to Plugin API key reset

Description

The WooCommerce UPS Shipping – Live Rates and Access Points plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the delete_oauth_data function in all versions up to, and including, 2.3.12. This makes it possible for authenticated attackers, with Subscriber-level access and above, to delete the plugin's API key.

Affects Plugins

References

Classification

Type
NO AUTHORISATION
CWE

Miscellaneous

Original Researcher
Peter Thaleikis
Verified
No

Timeline

Publicly Published
2024-10-24 (about 1 year ago)
Added
2024-10-24 (about 1 year ago)
Last Updated
2024-10-29 (about 1 year ago)

Other