WordPress Advanced WC Analytics Missing Authorization Vulnerability Allowing Access Control Bypass
Vulnerability
A missing authorization vulnerability has been identified in the WordPress Advanced WC Analytics plugin, specifically in versions through 3.19.0. This vulnerability allows for the exploitation of improperly configured access control levels, potentially leading to unauthorized changes in settings.
Impact
Exploitation of this vulnerability could result in unauthorized access to settings, allowing attackers to make changes that could affect the functionality or security of the WordPress site.
Remediation
Users are advised to update to a version of the Advanced WC Analytics plugin that is later than 3.19.0. For those using Patchstack, a mitigation rule has been issued to block attacks until an official patch is available.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
