Description
WordPress Plugin YITH WooCommerce Zoom Magnifier is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently modify plugin options. WordPress Plugin YITH WooCommerce Zoom Magnifier version 1.3.11 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 1.3.12 or latest
References
https://blog.nintechnet.com/authenticated-settings-change-vulnerability-in-yit-plugin-framework/
https://plugins.svn.wordpress.org/yith-woocommerce-zoom-magnifier/trunk/README.txt
Related Vulnerabilities
WordPress 4.0.x Cross-Site Scripting Vulnerability (4.0 - 4.0.8)
Oracle JRE CVE-2017-10293 Vulnerability (CVE-2017-10293)
OpenSSL Other Vulnerability (CVE-2005-1797)
CubeCart Permissions, Privileges, and Access Controls Vulnerability (CVE-2009-3904)
WordPress Plugin White Label CMS Cross-Site Scripting (1.5.2)