PT-2018-10717 · Multidots · Multidots Woo Checkout For Digital Goods

Publicado

2018-05-31

·

Atualizado

2018-06-29

·

CVE-2018-11633

CVSS v3.1

6.5

Média

VetorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions MULTIDOTS Woo Checkout for Digital Goods plugin version 2.1
Description An issue allows attackers to change plugin settings by tricking an admin user into visiting a crafted URL. The woo checkout settings page function in the file class-woo-checkout-for-digital-goods-admin.php lacks checks against Cross-site request forgery (CSRF) and user capabilities, specifically when interacting with wp-admin/admin-post.php.
Recommendations For MULTIDOTS Woo Checkout for Digital Goods plugin version 2.1, as a temporary workaround, consider disabling the woo checkout settings page function until a patch is available. Restrict access to the class-woo-checkout-for-digital-goods-admin.php file to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

CSRF

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2018-11633

Produtos afetados

Multidots Woo Checkout For Digital Goods