CVE-2020-36696

HIGH

Product Input Fields for WooCommerce <= 1.2.6 - Unauthenticated Authorization Bypass via handle_downloads()

Title source: llm
STIX 2.1

Description

The Product Input Fields for WooCommerce plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the handle_downloads() function in versions up to, and including, 1.2.6. This makes it possible for unauthenticated attackers to download files from the vulnerable service.

Scores

CVSS v3 7.5
EPSS 0.0109
EPSS Percentile 61.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-285 CWE-862
Status published
Products (2)
tychesoftwares/Product Input Fields for WooCommerce < 1.2.6
tychesoftwares/product_input_fields_for_woocommerce < 1.2.7
Published Jun 07, 2023
Tracked Since Feb 18, 2026