What the vulnerability does
01Description
Broken Access Control vulnerability in YIKES Inc. Custom Product Tabs for WooCommerce plugin <= 1.7.7 at WordPress leading to &yikes-the-content-toggle option update.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
What the vulnerability does
Broken Access Control vulnerability in YIKES Inc. Custom Product Tabs for WooCommerce plugin <= 1.7.7 at WordPress leading to &yikes-the-content-toggle option update.
Explanation of Vulnerability in Simple Terms
The Custom Product Tabs for WooCommerce plugin through version 1.7.7 does not properly validate user authentication, allowing unauthenticated attackers to modify product tab data via network requests. The vulnerability requires no user interaction and affects the integrity of product information stored in the plugin. Site administrators should update to a version newer than 1.7.7 immediately.
What an attacker can do
Modify product tab content without logging in to the site.
Potential impact on your site
Product tab data can be altered by anyone, potentially displaying incorrect or malicious information to customers.
Conditions required to exploit
Network access only; no authentication or user interaction required.
Key dates
External resources
Related vulnerabilities