CVE-2018-11579

MEDIUM

WooCommerce Category Banner Management 1.1.0 - Unauthenticated Settings Change

Title source: llm
STIX 2.1

Description

class-woo-banner-management.php in the MULTIDOTS WooCommerce Category Banner Management plugin 1.1.0 for WordPress has an Unauthenticated Settings Change Vulnerability, related to certain wp_ajax_nopriv_ usage. Anyone can change the plugin's setting by simply sending a request with a wbm_save_shop_page_banner_data action.

Scores

CVSS v3 5.3
EPSS 0.0095
EPSS Percentile 56.6%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

Details

CWE
CWE-287
Status published
Products (1)
multidots/woocommerce_category_banner_management 1.1.0
Published May 31, 2018
Tracked Since Feb 18, 2026