CVE-2018-11579
31.05.2018, 01:29
class-woo-banner-management.php in the MULTIDOTS WooCommerce Category Banner Management plugin 1.1.0 for WordPress has an Unauthenticated Settings Change Vulnerability, related to certain wp_ajax_nopriv_ usage. Anyone can change the plugin's setting by simply sending a request with a wbm_save_shop_page_banner_data action.Enginsight
Vendor | Product | Version |
---|---|---|
multidots | woocommerce_category_banner_management | 1.1.0 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References