PT-2024-11738 · Villatheme · Villatheme Curcy
Muhammad Daffa
·
Published
2024-12-13
·
Updated
2024-12-15
·
CVE-2022-46796
CVSS v3.1
6.5
Medium
| AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
VillaTheme CURCY versions 2.1.25 and earlier
Description
The issue is related to a Missing Authorization vulnerability, allowing exploitation of incorrectly configured access control security levels. This enables unauthenticated settings changes, potentially leading to exploitation. The vulnerability affects the Woo Multi Currency plugin for WordPress.
Recommendations
Update to the latest version to secure your site, as the latest version contains a fix for this issue.
As a temporary workaround, consider restricting access to the vulnerable plugin until a patch is available.
Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Villatheme Curcy