Security Advisory

CVE-2018-11579

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2018-05-31 01:00:00
Last updated 2024-09-16 22:03:03
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

class-woo-banner-management.php in the MULTIDOTS WooCommerce Category Banner Management plugin 1.1.0 for WordPress has an Unauthenticated Settings Change Vulnerability, related to certain wp_ajax_nopriv_ usage. Anyone can change the plugin's setting by simply sending a request with a wbm_save_shop_page_banner_data action.