Description
WordPress Plugin YITH WooCommerce Compare is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently modify plugin options. WordPress Plugin YITH WooCommerce Compare version 2.3.13 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 2.3.15 or latest
References
https://blog.nintechnet.com/authenticated-settings-change-vulnerability-in-yit-plugin-framework/
https://plugins.svn.wordpress.org/yith-woocommerce-compare/trunk/README.txt
Related Vulnerabilities
WordPress Plugin Gravity Forms Constant Contact Cross-Site Scripting (1.0.5)
Dot CMS Server-Side Request Forgery (SSRF) Vulnerability (CVE-2022-37033)
Ruby Out-of-bounds Write Vulnerability (CVE-2017-11465)
WordPress Other Vulnerability (CVE-2007-3544)
WordPress Plugin MStore API-Create Native Android & iOS Apps On The Cloud Security Bypass (2.1.5)