What the vulnerability does
01Description
Missing Authorization vulnerability in YITH YITH WooCommerce Account Funds Premium.This issue affects YITH WooCommerce Account Funds Premium: from n/a through 1.33.0.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
What the vulnerability does
Missing Authorization vulnerability in YITH YITH WooCommerce Account Funds Premium.This issue affects YITH WooCommerce Account Funds Premium: from n/a through 1.33.0.
Explanation of Vulnerability in Simple Terms
YITH WooCommerce Account Funds Premium versions up to 1.33.0 lack proper authorization checks on certain operations. An authenticated user with low privileges can modify account fund data they should not have access to. This allows unauthorized changes to fund balances or transactions. Update to a version newer than 1.33.0.
What an attacker can do
Modify account fund balances or transactions belonging to other users or restricted accounts.
Potential impact on your site
Users' account fund balances can be altered by other customers, leading to financial disputes and loss of trust.
Conditions required to exploit
Attacker must have a low-privilege account on the site (e.g., customer or subscriber role).
Key dates
External resources
Related vulnerabilities