Addonify WooCommerce Wishlist Missing Authorization Vulnerability Allowing Settings Change
Vulnerability
A missing authorization vulnerability has been identified in the Addonify WooCommerce Wishlist plugin, specifically in versions through 2.0.15. This vulnerability arises from incorrectly configured access control, allowing unauthorized users to exploit the issue and change settings within the plugin.
Impact
Exploitation of this vulnerability could lead to unauthorized changes in plugin settings, potentially allowing for further exploitation or manipulation of the WooCommerce wishlist functionality.
Remediation
Users of the Addonify WooCommerce Wishlist plugin should update to version 2.0.16 or later. Patchstack users can enable auto-update for vulnerable plugins.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
