VulnerabilityModified
CVE-2019-16251
plugin-fw/lib/yit-plugin-panel-wc.php in the YIT Plugin Framework through 3.3.8 for WordPress allows authenticated options changes.
MEDIUM 4.3EPSS 0.95%
Does this matter?
Lower severity and a low EPSS score (0.95%). Track it; it rarely justifies an emergency change on its own.
Description
plugin-fw/lib/yit-plugin-panel-wc.php in the YIT Plugin Framework through 3.3.8 for WordPress allows authenticated options changes.
- CVSS 3.1
- 4.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
- EPSS
- 0.95% probability · 59th percentile
- CISA KEV
- Not listed
- Affected
- yithemes/yith woocommerce wishlist · yithemes/yith woocommerce compare · yithemes/yith woocommerce quick view · yithemes/yith woocommerce zoom magnifier · yithemes/yith woocommerce ajax search · yithemes/yith woocommerce badge management · yithemes/yith woocommerce brands add-on · yithemes/yith woocommerce request a quote · yithemes/yith woocommerce social login · yithemes/yith woocommerce order tracking · yithemes/yith woocommerce pdf invoice and shipping list · yithemes/yith pre-order for woocommerce · yithemes/yith woocommerce advanced reviews · yithemes/yith woocommerce product add-ons · yithemes/yith woocommerce gift cards · yithemes/yith woocommerce subscription · yithemes/yith woocommerce affiliates · yithemes/yith woocommerce cart messages · yithemes/yith woocommerce product bundles · yithemes/yith woocommerce frequently bought together · +18 more
- Source
- cve@mitre.org
References
- https://blog.nintechnet.com/authenticated-settings-change-vulnerability-in-yit-plugin-framework/Third Party Advisory
- https://wpvulndb.com/vulnerabilities/9932Third Party Advisory
- https://blog.nintechnet.com/authenticated-settings-change-vulnerability-in-yit-plugin-framework/Third Party Advisory
- https://wpvulndb.com/vulnerabilities/9932Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.