Vulnerabilities
Vulnerable Software
The Product Expiry for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'save_settings' function in versions up to, and including, 2.5. This makes it possible for authenticated attackers, with subscriber-level permissions or above to update plugin settings.
CVSS Score
5.4
EPSS Score
0.0
Published
2024-01-03


Contact Us

Shodan ® - All rights reserved