Description
WordPress Plugin YITH WooCommerce Badge Management is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently modify plugin options. WordPress Plugin YITH WooCommerce Badge Management version 1.3.19 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 1.3.21 or latest
References
https://blog.nintechnet.com/authenticated-settings-change-vulnerability-in-yit-plugin-framework/
https://plugins.svn.wordpress.org/yith-woocommerce-badges-management/trunk/README.txt
Related Vulnerabilities
WordPress Plugin Tutor LMS-eLearning and online course solution Multiple Vulnerabilities (1.7.6)
WordPress Plugin Share and Follow 'admin.php' Cross-Site Scripting (1.80.3)
SharePoint CVE-2023-33160 Vulnerability (CVE-2023-33160)
WordPress Plugin Jetpack-WP Security, Backup, Speed, & Growth Cross-Site Scripting (3.9.1)
Oracle Database Server CVE-2024-20995 Vulnerability (CVE-2024-20995)