cleantalk
Vulnerabilities and Security Researches

Product Expiry for WooCommerce, 3b66effa10c8c27ee99c2ded56fe6911f34a4f72

Published on
-
Research Description
Product Expiry for WooCommerce [product-expiry-for-woocommerce] < 2.6 WordPress Product Expiry for WooCommerce Plugin <= 2.5 is vulnerable to Broken Access Control Update the WordPress Product Expiry for WooCommerce plugin to the latest available version (at least 2.6). LVT-tholv2k discovered and reported this Broken Access Control vulnerability in WordPress Product Expiry for WooCommerce Plugin. A broken access control issue refers to a missing authorization, authentication or nonce token check in a function that could lead to an unprivileged user to executing a certain higher privileged action. This vulnerability has been fixed in version 2.6. Have additional information or questions about this entry? Get in touch.
Affected versions
max 2.6.
Status
vulnerable