T
he TI WooCommerce Wishlist and TI WooCommerce Wishlist Pro plugins for WordPress are vulnerable to an Options Change vulnerability in versions up to, and including, 1.21.11 and 1.21.4 via the 'ti-woocommerce-wishlist/includes/export.class.php' file. This makes it possible for authenticated attackers to gain otherwise restricted access to the vulnerable blog and update any settings.
References
| Link | Resource |
|---|---|
| https://blog.nintechnet.com/critical-zero-day-vulnerability-fixed-in-wordpress-ti-woocommerce-wishlist-plugin/ | Exploit Third Party Advisory |
| https://templateinvaders.com/changelogs/ti-woocommerce-wishlist-plugin-changelog/ | Release Notes |
| https://wpscan.com/vulnerability/2e2fb815-7cca-4e6c-b466-179337fe99ee | Third Party Advisory |
| https://www.wordfence.com/threat-intel/vulnerabilities/id/d60b5741-5496-4e87-bcb0-adaa0db07d90?source=cve | Third Party Advisory |
| https://blog.nintechnet.com/critical-zero-day-vulnerability-fixed-in-wordpress-ti-woocommerce-wishlist-plugin/ | Exploit Third Party Advisory |
| https://templateinvaders.com/changelogs/ti-woocommerce-wishlist-plugin-changelog/ | Release Notes |
| https://wpscan.com/vulnerability/2e2fb815-7cca-4e6c-b466-179337fe99ee | Third Party Advisory |
| https://www.wordfence.com/threat-intel/vulnerabilities/id/d60b5741-5496-4e87-bcb0-adaa0db07d90?source=cve | Third Party Advisory |
Configurations
Configuration 1 (hide)
|
History
21 Nov 2024, 05:30
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://blog.nintechnet.com/critical-zero-day-vulnerability-fixed-in-wordpress-ti-woocommerce-wishlist-plugin/ - Exploit, Third Party Advisory | |
| References | () https://templateinvaders.com/changelogs/ti-woocommerce-wishlist-plugin-changelog/ - Release Notes | |
| References | () https://wpscan.com/vulnerability/2e2fb815-7cca-4e6c-b466-179337fe99ee - Third Party Advisory | |
| References | () https://www.wordfence.com/threat-intel/vulnerabilities/id/d60b5741-5496-4e87-bcb0-adaa0db07d90?source=cve - Third Party Advisory | |
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 8.8 |
Information
Published : 2023-06-07 02:15
Updated : 2024-11-21 05:30
NVD link : CVE-2020-36725
Mitre link : CVE-2020-36725
CVE.ORG link : CVE-2020-36725
JSON object : View
Products Affected
CWE
CWE-862
Missing Authorization