CVE-2021-4379: WooCommerce Multi Currency <= 2.1.17 - Missing Authorization
Published Jun 7, 2023
·Updated
The WooCommerce Multi Currency plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the wmcbulkfixedprice function in versions up to, and including, 2.1.17. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to make changes to product prices.
Affected Software
1 affected component
Villatheme Woocommerce Multi Currency Wordpress<2.1.18
Event History
Jun 7, 2023
CVE Published
via MITRE·12:43 PM
Data Sourced
via MITRE·12:43 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·01:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2021-4379.
2
What is the affected software?
The affected software is the WooCommerce Multi Currency plugin for WordPress.
3
What is the severity level of CVE-2021-4379?
CVE-2021-4379 has a severity level of medium.
4
What is the vulnerability description?
The WooCommerce Multi Currency plugin for WordPress is vulnerable to authorization bypass due to a missing capability check.
5
How can this vulnerability be fixed?
To fix this vulnerability, users should update to version 2.1.18 or higher of the WooCommerce Multi Currency plugin.