Description
WordPress Plugin Product Addons & Fields for WooCommerce is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently call an AJAX action and set arbitrary settings. WordPress Plugin Product Addons & Fields for WooCommerce version 23.9 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 24.0 or latest
References
Related Vulnerabilities
Oracle Application Server Other Vulnerability (CVE-2005-3450)
WordPress Plugin Tabs-Responsive Tabs with WooCommerce Product Tab Extension Security Bypass (3.6.0)
SugarCRM Improper Input Validation Vulnerability (CVE-2011-0745)
WordPress Plugin Advanced Custom Fields (ACF) 'acf_abspath' Parameter Remote File Include (3.5.1)