Description
WordPress Plugin YITH WooCommerce Badge Management is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently modify plugin options. WordPress Plugin YITH WooCommerce Badge Management version 1.3.19 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 1.3.21 or latest
References
https://blog.nintechnet.com/authenticated-settings-change-vulnerability-in-yit-plugin-framework/
https://plugins.svn.wordpress.org/yith-woocommerce-badges-management/trunk/README.txt
Related Vulnerabilities
TYPO3 Deserialization of Untrusted Data Vulnerability (CVE-2020-11067)
MySQL CVE-2012-3144 Vulnerability (CVE-2012-3144)
Oracle JRE CVE-2019-2962 Vulnerability (CVE-2019-2962)
SugarCRM Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2011-3803)
Telerik Web UI Improper Input Validation Vulnerability (CVE-2017-11357)