PT-2021-23598 · WordPress · Variation Swatches For Woocommerce

Published

2021-12-14

·

Updated

2022-08-09

·

CVE-2021-42367

CVSS v3.1

6.4

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Variation Swatches for WooCommerce WordPress plugin versions up to and including 2.1.1
Description The issue allows attackers to inject arbitrary web scripts via several parameters in the ~/includes/class-menu-page.php file, due to missing authorization checks on the tawcvs save settings function. This enables low-level authenticated users, such as subscribers, to exploit the vulnerability.
Recommendations For versions up to and including 2.1.1, update to a version higher than 2.1.1 to resolve the issue. As a temporary workaround, consider restricting access to the tawcvs save settings function to prevent low-level authenticated users from exploiting the vulnerability.

Fix

Missing Authorization

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-42367

Affected Products

Variation Swatches For Woocommerce