9.9

CVE-2021-4347

Exploit

Advanced Shipment Tracking for WooCommerce <= 3.2.6 - Authenticated WordPress Options Change

The function update_shipment_status_email_status_fun in the plugin Advanced Shipment Tracking for WooCommerce in versions up to 3.2.6 is vulnerable to authenticated arbitrary options update. The function allows attackers (including those at customer level) to update any WordPress option in the database. Version 3.2.5 was initially released as a fix, but doesn't fully address the issue.
Mögliche Gegenmaßnahme
Advanced Shipment Tracking for WooCommerce: Update to version 3.2.7, or a newer patched version
Weitere Schwachstelleninformationen
SystemWordPress Plugin
Produkt Advanced Shipment Tracking for WooCommerce
Version * - 3.2.6
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
ZoremAdvanced Shipment Tracking For Woocommerce SwPlatformwordpress Version <= 3.2.6
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.09% 0.263
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 6.5 2.8 3.6
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
security@wordfence.com 9.9 3.1 6
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:H/A:H
CWE-862 Missing Authorization

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.