Description
WordPress Plugin YITH WooCommerce Cart Messages is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently modify plugin options. WordPress Plugin YITH WooCommerce Cart Messages version 1.4.3 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 1.4.5 or latest
References
https://blog.nintechnet.com/authenticated-settings-change-vulnerability-in-yit-plugin-framework/
https://plugins.svn.wordpress.org/yith-woocommerce-cart-messages/trunk/README.txt
Related Vulnerabilities
WordPress Plugin WP Construction Mode Cross-Site Request Forgery (3.31)
Oracle JRE CVE-2012-5071 Vulnerability (CVE-2012-5071)
Python Improper Restriction of XML External Entity Reference Vulnerability (CVE-2022-48565)
WordPress Plugin SupportEzzy Ticket System Cross-Site Scripting (1.2.5)
WordPress Plugin Booking Calendar-Appointment Booking-BookIt Unspecified Vulnerability (2.3.8)