Description
WordPress Plugin YITH WooCommerce Product Bundles is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently modify plugin options. WordPress Plugin YITH WooCommerce Product Bundles version 1.1.15 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 1.1.17 or latest
References
https://blog.nintechnet.com/authenticated-settings-change-vulnerability-in-yit-plugin-framework/
https://plugins.svn.wordpress.org/yith-woocommerce-product-bundles/trunk/README.txt
Related Vulnerabilities
WordPress Plugin API Bearer Auth Cross-Site Scripting (20181229)
WordPress Plugin Aspose DOC Exporter Arbitrary File Download (1.0)
WordPress Plugin WP Google Fonts Cross-Site Scripting (3.1.3)
WordPress Plugin Chat-Support Board-WordPress Chat Multiple SQL Injection Vulnerabilities (3.3.3)
WordPress Plugin Leaky Paywall Cross-Site Scripting (4.16.5)