CRITICAL · 9.9

CVE-2021-4347

The function update_shipment_status_email_status_fun in the plugin Advanced Shipment Tracking for WooCommerce in versions up to 3.2.6 is vulnerable to authenticated arbitrary options update. The funct...

Vulnerability Description

The function update_shipment_status_email_status_fun in the plugin Advanced Shipment Tracking for WooCommerce in versions up to 3.2.6 is vulnerable to authenticated arbitrary options update. The function allows attackers (including those at customer level) to update any WordPress option in the database. Version 3.2.5 was initially released as a fix, but doesn't fully address the issue.

CVSS Score

9.9

CRITICAL

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:H/A:H
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
CHANGED
Confidentiality
LOW
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
ZoremAdvanced Shipment Tracking For Woocommerce<= 3.2.6

Related Weaknesses (CWE)

References

FAQ

What is CVE-2021-4347?

CVE-2021-4347 is a vulnerability with a CVSS score of 9.9 (CRITICAL). The function update_shipment_status_email_status_fun in the plugin Advanced Shipment Tracking for WooCommerce in versions up to 3.2.6 is vulnerable to authenticated arbitrary options update. The funct...

How severe is CVE-2021-4347?

CVE-2021-4347 has been rated CRITICAL with a CVSS base score of 9.9/10. This is considered a critical vulnerability requiring immediate attention.

Is there a patch for CVE-2021-4347?

Check the references section above for vendor advisories and patch information. Affected products include: Zorem Advanced Shipment Tracking For Woocommerce.