1 results (0.008 seconds)

CVSS: 6.5EPSS: %CPEs: 1EXPL: 0

The Japanized For WooCommerce plugin for WordPress is vulnerable to unauthorized access and modification due to missing capability checks on several functions called via REST API function in versions up to, and including, 2.6.4. This makes it possible for unauthenticated attackers to perform a wide variety of actions such as updating the plugin's settings and retrieving information about settings. • CWE-862: Missing Authorization •