cleantalk
Vulnerabilities and Security Researches

Wishlist for WooCommerce, 44328ad4a73527e247087ea8c83a111a265d4b16

Published on
Aug 12, 2019
Research Description
JVM WooCommerce Wishlist [jvm-woocommerce-wishlist] < 1.2.7 JVM WooCommerce Wishlist <= 1.2.6 - Insecure Direct Object Reference The JVM WooCommerce Wishlist plugin for WordPress is vulnerable to Insecure Direct Object Reference via the 'user_id' parameter in versions up to, and including, 1.2.6. This makes it possible for unauthenticated attackers to bypass authorization protocols and access otherwise restricted system resources.
Affected versions
max 1.2.7.
Status
vulnerable