9.9

CVE-2021-4347

Exploit

Advanced Shipment Tracking for WooCommerce <= 3.2.6 - Authenticated WordPress Options Change

Advanced Shipment Tracking for WooCommerce <= 3.2.6 - Authenticated WordPress Options Change

The function update_shipment_status_email_status_fun in the plugin Advanced Shipment Tracking for WooCommerce in versions up to 3.2.6 is vulnerable to authenticated arbitrary options update. The function allows attackers (including those at customer level) to update any WordPress option in the database. Version 3.2.5 was initially released as a fix, but doesn't fully address the issue.
Mögliche Gegenmaßnahme
Advanced Shipment Tracking for WooCommerce: Update to version 3.2.7, or a newer patched version
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
ZoremAdvanced Shipment Tracking For Woocommerce SwPlatformwordpress Version <= 3.2.6
Weitere Schwachstelleninformationen
SystemWordPress Plugin
Produkt Advanced Shipment Tracking for WooCommerce
Version *-3.2.6
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.65% 0.464
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 6.5 2.8 3.6
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
security@wordfence.com 9.9 3.1 6
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:H/A:H
CWE-862 Missing Authorization

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

https://blog.nintechnet.com/wordpress-advanced-shipment-tracking-for-woocommerce-fixed-critical-vulnerability/
Exploit
https://www.wordfence.com/threat-intel/vulnerabilities/id/4174b47a-75d0-4ada-bd4d-efbaf0b1a049?source=cve
Third Party Advisory
https://www.wordfence.com/threat-intel/vulnerabilities/id/4174b47a-75d0-4ada-bd4d-efbaf0b1a049
Third Party Advisory