CVE · Medium

CVE-2024-0870 — YITH WooCommerce Gift Cards [yith-woocommerce-gift-cards] < 4.13.0

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2024-0870 YITH WooCommerce Gift Cards [yith-woocommerce-gift-cards] < 4.13.0 Improper Authorization Medium 5.3 < 4.13.0 4.13.0 2024-05-13

CVE-2024-0870

The YITH WooCommerce Gift Cards plugin contains a flaw in versions 4.12.0 and earlier where the 'save_mail_status' and 'save_email_settings' functions lack proper capability verification. This oversight allows unauthenticated attackers to change WooCommerce configuration settings without authorization. The vulnerability affects all installations running the impacted versions prior to 4.13.0.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.