PT-2023-11867 · Unknown · Ti Woocommerce Wishlist

Jerome Bruandet

·

Published

2023-06-07

·

Updated

2023-06-16

·

CVE-2020-36725

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions TI WooCommerce Wishlist versions up to 1.21.11 TI WooCommerce Wishlist Pro versions up to 1.21.4
Description The issue allows authenticated attackers to gain restricted access to the vulnerable blog and update any settings due to an Options Change vulnerability. This is possible via the 'ti-woocommerce-wishlist/includes/export.class.php' file.
Recommendations For TI WooCommerce Wishlist versions up to 1.21.11, update to a version later than 1.21.11 to resolve the issue. For TI WooCommerce Wishlist Pro versions up to 1.21.4, update to a version later than 1.21.4 to resolve the issue. As a temporary workaround, consider restricting access to the export.class.php file until a patch is available.

Exploit

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2020-36725

Affected Products

Ti Woocommerce Wishlist