CVE-2019-11807

Severity CVSS v4.0:
Pending analysis
Type:
CWE-434 Unrestricted Upload of File with Dangerous Type
Publication date:
06/05/2019
Last modified:
24/08/2020

Description

The WooCommerce Checkout Manager plugin before 4.3 for WordPress allows media deletion via the wp-admin/admin-ajax.php?action=update_attachment_wccm wccm_default_keys_load parameter because of a nopriv_ registration and a lack of capabilities checks.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:visser:woocommerce_checkout_manager:*:*:*:*:*:wordpress:*:* 4.3 (excluding)