WooCommerce Chained Products < 2.12.0 - Missing Authorization to Arbitrary Options Update
criticalThe WooCommerce Chained Products plugin for WordPress is vulnerable to authorization bypass due to a missing capability check when updating its settings in versions up to, and including, 2.12.0. This makes it possible for unauthenticated attackers to update arbitrary options that may not belong to the plugin. However,...
- CVSS:
- 9.1
- Affected:
- up to 2.12.0
- Fixed in:
- 2.12.0
- Disclosed:
- Jan 4, 2023