YIT Plugin Framework <= 3.3.8 - Authenticated Settings Change
mediumVarious versions of a various YITH WooCommerce plugins that use the YIT Plugin Framework through 3.3.8 are vulnerable to authorization bypass due to a missing capability check in the the 'save_toggle_element_options' function in .plugin-fw/lib/yit-plugin-panel-wc.php. This allows authenticated users with subscriber-lev...
- CVSS:
- 4.3
- Affected:
- up to 1.3.2
- Fixed in:
- 1.3.4
- Disclosed:
- Oct 31, 2019