Description
WordPress Plugin YITH WooCommerce Frequently Bought Together is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently modify plugin options. WordPress Plugin YITH WooCommerce Frequently Bought Together version 1.2.10 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 1.2.12 or latest
References
https://blog.nintechnet.com/authenticated-settings-change-vulnerability-in-yit-plugin-framework/
https://plugins.svn.wordpress.org/yith-woocommerce-frequently-bought-together/trunk/README.txt
Related Vulnerabilities
WordPress Plugin YITH WooCommerce Order Tracking Security Bypass (1.2.10)
PostgreSQL Permissions, Privileges, and Access Controls Vulnerability (CVE-2016-0766)
Coppermine Cross-site Scripting (XSS) Vulnerability (CVE-2015-3921)
Apache Tomcat Use of Incorrectly-Resolved Name or Reference Vulnerability (CVE-2021-24122)
WordPress Plugin Menu Creator 'updateSortOrder.php' SQL Injection (1.1.7)