Description
WordPress Plugin YITH WooCommerce Cart Messages is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently modify plugin options. WordPress Plugin YITH WooCommerce Cart Messages version 1.4.3 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 1.4.5 or latest
References
https://blog.nintechnet.com/authenticated-settings-change-vulnerability-in-yit-plugin-framework/
https://plugins.svn.wordpress.org/yith-woocommerce-cart-messages/trunk/README.txt
Related Vulnerabilities
WordPress 4.0.x Multiple Vulnerabilities (4.0 - 4.0.30)
WordPress Plugin ToolBar to Share Cross-Site Request Forgery (2.0)
WordPress Plugin Testimonial Slider Multiple Cross-Site Scripting Vulnerabilities (1.2.5)
PHP Out-of-bounds Read Vulnerability (CVE-2018-10549)
TYPO3 Deserialization of Untrusted Data Vulnerability (CVE-2019-12747)