Product Stock Manager < 1.0.5 - Missing Authorization and Cross-Site Request Forgery
highThe Product Stock Manager plugin for WordPress is vulnerable to authorization bypass due to missing capability checks on several AJAX actions such as af_sm_set_checkbox_status in versions up to, and including, 1.0.5. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to inv...
- CVSS:
- 8.1
- Affected:
- up to 1.0.5
- Fixed in:
- 1.0.5
- Disclosed:
- Oct 17, 2022