Description
WordPress Plugin YITH WooCommerce Quick View is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently modify plugin options. WordPress Plugin YITH WooCommerce Quick View version 1.3.13 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 1.3.15 or latest
References
https://blog.nintechnet.com/authenticated-settings-change-vulnerability-in-yit-plugin-framework/
https://plugins.svn.wordpress.org/yith-woocommerce-quick-view/trunk/README.txt
Related Vulnerabilities
WordPress Plugin Photo Gallery, Images, Slider in Rbs Image Gallery Security Bypass (2.0.15)
Drupal Core 7.x Arbitrary File Overwrite (7.0 - 7.77)
WordPress Plugin Gallery-Flagallery Photo Portfolio Cross-Site Request Forgery (5.3.6)
WordPress Plugin WP-Download 'dl_id' Parameter SQL Injection (1.2)
WordPress Plugin Under Construction Unspecified Vulnerability (3.85)