7.5

CVE-2020-36696

Exploit

Product Input Fields for WooCommerce <= 1.2.6 - Missing Authorization

Product Input Fields for WooCommerce <= 1.2.6 - Missing Authorization

The Product Input Fields for WooCommerce plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the handle_downloads() function in versions up to, and including, 1.2.6. This makes it possible for unauthenticated attackers to download files from the vulnerable service.
Mögliche Gegenmaßnahme
Product Input Fields for WooCommerce: Update to version 1.2.7, or a newer patched version
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
TychesoftwaresProduct Input Fields For Woocommerce SwPlatformwordpress Version < 1.2.7
Weitere Schwachstelleninformationen
SystemWordPress Plugin
Produkt Product Input Fields for WooCommerce
Version *-1.2.6
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.09% 0.61
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
security@wordfence.com 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CWE-285 Improper Authorization

The product does not perform or incorrectly performs an authorization check when an actor attempts to access a resource or perform an action.

CWE-862 Missing Authorization

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

https://blog.nintechnet.com/high-severity-vulnerability-fixed-in-product-input-fields-for-woocommerce/
Exploit
https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=2349889%40product-input-fields-for-woocommerce&new=2349889%40product-input-fields-for-woocommerce&sfp_email=&sfph_mail=
Patch
https://wpscan.com/vulnerability/15f345e6-fc53-4bac-bc5a-de898181ea74
Exploit
https://www.wordfence.com/threat-intel/vulnerabilities/id/01e41573-9329-48e1-9191-e8e1532f7afc?source=cve
Third Party Advisory
https://www.wordfence.com/threat-intel/vulnerabilities/id/01e41573-9329-48e1-9191-e8e1532f7afc
Third Party Advisory