Vulnerability Description
plugin-fw/lib/yit-plugin-panel-wc.php in the YIT Plugin Framework through 3.3.8 for WordPress allows authenticated options changes.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Yithemes | Yith Woocommerce Wishlist | <= 2.2.13 |
| Yithemes | Yith Woocommerce Compare | <= 2.3.13 |
| Yithemes | Yith Woocommerce Quick View | <= 1.3.13 |
| Yithemes | Yith Woocommerce Zoom Magnifier | <= 1.3.11 |
| Yithemes | Yith Woocommerce Ajax Search | <= 1.6.9 |
| Yithemes | Yith Woocommerce Badge Management | <= 1.3.19 |
| Yithemes | Yith Woocommerce Brands Add-On | <= 1.3.6 |
| Yithemes | Yith Woocommerce Request A Quote | <= 1.4.7 |
| Yithemes | Yith Woocommerce Social Login | <= 1.3.4 |
| Yithemes | Yith Woocommerce Order Tracking | <= 1.2.10 |
| Yithemes | Yith Woocommerce Pdf Invoice And Shipping List | <= 1.2.12 |
| Yithemes | Yith Pre-Order For Woocommerce | <= 1.1.9 |
| Yithemes | Yith Woocommerce Advanced Reviews | <= 1.3.9 |
| Yithemes | Yith Woocommerce Product Add-Ons | <= 1.5.21 |
| Yithemes | Yith Woocommerce Gift Cards | <= 1.3.7 |
| Yithemes | Yith Woocommerce Subscription | <= 1.3.4 |
| Yithemes | Yith Woocommerce Affiliates | <= 1.6.3 |
| Yithemes | Yith Woocommerce Cart Messages | <= 1.4.3 |
| Yithemes | Yith Woocommerce Product Bundles | <= 1.1.15 |
| Yithemes | Yith Woocommerce Frequently Bought Together | <= 1.2.10 |
References
- https://blog.nintechnet.com/authenticated-settings-change-vulnerability-in-yit-pThird Party Advisory
- https://wpvulndb.com/vulnerabilities/9932Third Party Advisory
- https://blog.nintechnet.com/authenticated-settings-change-vulnerability-in-yit-pThird Party Advisory
- https://wpvulndb.com/vulnerabilities/9932Third Party Advisory
FAQ
What is CVE-2019-16251?
CVE-2019-16251 is a vulnerability with a CVSS score of 4.3 (MEDIUM). plugin-fw/lib/yit-plugin-panel-wc.php in the YIT Plugin Framework through 3.3.8 for WordPress allows authenticated options changes.
How severe is CVE-2019-16251?
CVE-2019-16251 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-16251?
Check the references section above for vendor advisories and patch information. Affected products include: Yithemes Yith Woocommerce Wishlist, Yithemes Yith Woocommerce Compare, Yithemes Yith Woocommerce Quick View, Yithemes Yith Woocommerce Zoom Magnifier, Yithemes Yith Woocommerce Ajax Search.