Description
WordPress Plugin YITH Desktop Notifications for WooCommerce is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently modify plugin options. WordPress Plugin YITH Desktop Notifications for WooCommerce version 1.2.7 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 1.2.8 or latest
References
https://blog.nintechnet.com/authenticated-settings-change-vulnerability-in-yit-plugin-framework/
https://plugins.svn.wordpress.org/yith-desktop-notifications-for-woocommerce/trunk/readme.txt
Related Vulnerabilities
MySQL CVE-2023-21878 Vulnerability (CVE-2023-21878)
WebLogic CVE-2021-2214 Vulnerability (CVE-2021-2214)
WordPress Plugin Email Users Cross-Site Scripting (4.7.5)
WordPress Plugin Similar Posts-Best Related Posts for WordPress Remote Code Execution (3.1.5)
OpenSSL Access of Resource Using Incompatible Type ('Type Confusion') Vulnerability (CVE-2024-6119)