JVM WooCommerce Wishlist <= 1.2.6 - Insecure Direct Object Reference



Description
Unauthenticated attackers could update the wish-list of arbitrary users

Affects Plugin

fixed in version 1.2.7

References

URL https://plugins.trac.wordpress.org/changeset/2138285

Classification

Type AUTHBYPASS
OWASP Top 10 A2: Broken Authentication and Session Management
CWE CWE-287

Miscellaneous

Views 1598
Verified No
WPVDB ID 9960

Timeline

Publicly Published 2019-08-12 (11 months ago)
Added 2019-12-02 (7 months ago)
Last Updated 2019-12-02 (7 months ago)

Our Other Services

Online WordPress Vulnerability Scanner WPScan WordPress Security Plugin