Description
WordPress Plugin YITH WooCommerce Cart Messages is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently modify plugin options. WordPress Plugin YITH WooCommerce Cart Messages version 1.4.3 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 1.4.5 or latest
References
https://blog.nintechnet.com/authenticated-settings-change-vulnerability-in-yit-plugin-framework/
https://plugins.svn.wordpress.org/yith-woocommerce-cart-messages/trunk/README.txt
Related Vulnerabilities
WebLogic CVE-2017-10063 Vulnerability (CVE-2017-10063)
WordPress Plugin ImageDrop 'ImageDrop.php' Blind SQL Injection (1.1.2)
WordPress 4.7.x Multiple Vulnerabilities (4.7 - 4.7.26)
MySQL CVE-2020-2806 Vulnerability (CVE-2020-2806)
Oracle Database Server Deserialization of Untrusted Data Vulnerability (CVE-2017-15095)