Wishlist and Compare for WooCommerce <= 1.0.4 - Authorization Bypass
highThe Wishlist and Compare for WooCommerce plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on several functions in versions up to, and including, 1.0.4. This makes it possible for unauthenticated attackers to edit plugin settings.
- CVSS:
- 7.5
- Affected:
- up to 1.0.4
- Fixed in:
- 1.0.5
- Disclosed:
- May 8, 2021