First published: Mon May 06 2019(Updated: )
The WooCommerce Checkout Manager plugin before 4.3 for WordPress allows media deletion via the wp-admin/admin-ajax.php?action=update_attachment_wccm wccm_default_keys_load parameter because of a nopriv_ registration and a lack of capabilities checks.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Visser Woocommerce Checkout Manager | <4.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2019-11807.
The severity of CVE-2019-11807 is high with a severity value of 7.5.
The affected software for CVE-2019-11807 is the WooCommerce Checkout Manager plugin before version 4.3 for WordPress.
An attacker can exploit CVE-2019-11807 by using the wp-admin/admin-ajax.php?action=update_attachment_wccm wccm_default_keys_load parameter to delete media files without proper authorization.
To fix CVE-2019-11807, you should update the WooCommerce Checkout Manager plugin to version 4.3 or later.