Lucene search

K
wpvulndbWpvulndbWPVDB-ID:8F7D97FF-A5BB-40CC-861B-5A868DD5C57A
HistoryJan 28, 2022 - 12:00 a.m.

Perfect Brands for WooCommerce < 2.0.5 - Subscriber+ Arbitrary Brand Creation

2022-01-2800:00:00
wpscan.com
22
woocommerce
arbitrary brand creation
ajax actions
authorization
csrf checks
security vulnerability

EPSS

0.001

Percentile

19.4%

The plugin does not have authorisation and CSRF checks in some of its AJAX actions, which could allow any authenticated users, such as subscriber to create arbitrary brands

EPSS

0.001

Percentile

19.4%

Related for WPVDB-ID:8F7D97FF-A5BB-40CC-861B-5A868DD5C57A