Description
WordPress Plugin YITH WooCommerce Waiting List is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently modify plugin options. WordPress Plugin YITH WooCommerce Waiting List version 1.3.9 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 1.3.11 or latest
References
https://blog.nintechnet.com/authenticated-settings-change-vulnerability-in-yit-plugin-framework/
https://plugins.svn.wordpress.org/yith-woocommerce-waiting-list/trunk/README.txt
Related Vulnerabilities
Joomla! Core 1.5.x Cross-Site Scripting (1.5.0 - 1.5.11)
WordPress Plugin RSS Includes Pages Cross-Site Scripting (3.6)
Liferay DXP Incorrect Authorization Vulnerability (CVE-2024-25149)
Microsoft SQL Server CVE-2023-23384 Vulnerability (CVE-2023-23384)
ATutor Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2016-2539)