What the vulnerability does
01Description
Missing Authorization vulnerability in Moreconvert Team MC Woocommerce Wishlist smart-wishlist-for-more-convert.This issue affects MC Woocommerce Wishlist: from n/a through <= 1.7.2.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
What the vulnerability does
Missing Authorization vulnerability in Moreconvert Team MC Woocommerce Wishlist smart-wishlist-for-more-convert.This issue affects MC Woocommerce Wishlist: from n/a through <= 1.7.2.
Explanation of Vulnerability in Simple Terms
MC Woocommerce Wishlist versions 1.7.2 and earlier lack proper authorization checks, allowing unauthenticated attackers to modify wishlist data via network requests. The vulnerability does not expose sensitive information but can alter wishlist contents. Site owners should update to a version newer than 1.7.2 to restore proper access controls.
What an attacker can do
Modify wishlist data without authentication or user interaction.
Potential impact on your site
Wishlist data can be altered by unauthorized users, affecting customer experience and data integrity.
Conditions required to exploit
Network access only; no authentication or user interaction required.
Key dates
External resources
Related vulnerabilities