Description
WordPress Plugin Product Addons & Fields for WooCommerce is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently call an AJAX action and set arbitrary settings. WordPress Plugin Product Addons & Fields for WooCommerce version 23.9 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 24.0 or latest
References
Related Vulnerabilities
Moodle Permissions, Privileges, and Access Controls Vulnerability (CVE-2014-0123)
WordPress Plugin Shopping Cart & eCommerce Store Information Disclosure (2.0.5)
Joomla Configuration Vulnerability (CVE-2008-3228)
WordPress 4.7.x Multiple Vulnerabilities (4.7 - 4.7.24)
WordPress Plugin Simple History Information Disclosure (1.0.7)