// For flags

CVE-2018-11579

Woocommerce Category Banner Management <= 1.1.0 - Missing Authorization

Severity Score

6.5
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

1
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

class-woo-banner-management.php in the MULTIDOTS WooCommerce Category Banner Management plugin 1.1.0 for WordPress has an Unauthenticated Settings Change Vulnerability, related to certain wp_ajax_nopriv_ usage. Anyone can change the plugin's setting by simply sending a request with a wbm_save_shop_page_banner_data action.

class-woo-banner-management.php en el plugin MULTIDOTS WooCommerce Category Banner Management 1.1.0 para WordPress tiene una vulnerabilidad de cambio de configuración sin autenticación, relacionada con un uso concreto de wp_ajax_nopriv_. Cualquier persona puede cambiar la configuración del plugin simplemente enviando una petición con una acción wbm_save_shop_page_banner_data.

*Credits: Jack K.
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
Low
Availability
Low
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
Low
Availability
None
Attack Vector
Network
Attack Complexity
Low
Authentication
None
Confidentiality
None
Integrity
Partial
Availability
None
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2018-05-29 CVE Published
  • 2018-05-30 CVE Reserved
  • 2024-09-16 CVE Updated
  • 2024-09-16 First Exploit
  • 2024-09-17 EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
CWE
  • CWE-287: Improper Authentication
  • CWE-862: Missing Authorization
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Multidots
Search vendor "Multidots"
Woocommerce Category Banner Management
Search vendor "Multidots" for product "Woocommerce Category Banner Management"
1.1.0
Search vendor "Multidots" for product "Woocommerce Category Banner Management" and version "1.1.0"
wordpress
Affected