What the vulnerability does
01Description
Unauthenticated Plugin Settings Change & Data Deletion vulnerabilities in WP Shop plugin <= 3.9.6 at WordPress.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L
What the vulnerability does
Unauthenticated Plugin Settings Change & Data Deletion vulnerabilities in WP Shop plugin <= 3.9.6 at WordPress.
Explanation of Vulnerability in Simple Terms
WP Shop versions 3.9.6 and earlier contain a vulnerability that allows unauthenticated attackers to modify data or disrupt site availability over the network. No special conditions or user interaction are required to exploit this issue. Site administrators should update to a version newer than 3.9.6 as soon as possible.
What an attacker can do
Modify site data or cause temporary unavailability without authentication.
Potential impact on your site
Your shop data could be altered or the site could become temporarily unavailable to visitors.
Conditions required to exploit
Network access only; no authentication or user interaction required.
Key dates
External resources
Related vulnerabilities