CVE · Medium

CVE-2019-16251 — YITH WooCommerce Gift Cards [yith-woocommerce-gift-cards] < 1.3.8

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2019-16251 YITH WooCommerce Gift Cards [yith-woocommerce-gift-cards] < 1.3.8 Medium 4.3 < 1.3.8 1.3.8 2019-10-31

CVE-2019-16251

The YITH WooCommerce Gift Cards plugin before version 1.3.8 contains an authorization bypass vulnerability in the YIT Plugin Framework up to version 3.3.8. The 'save_toggle_element_options' function in the plugin framework fails to verify user permissions before allowing changes to plugin settings. An authenticated user with only subscriber-level access or higher can exploit this flaw to modify arbitrary plugin configuration options.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.