HomeDefault status
affected
Any version
affected
Description
The Make Email Customizer for WooCommerce WordPress plugin through 1.0.6 lacks proper authorization checks and option validation in its AJAX actions, allowing any authenticated user, such as a Subscriber, to update arbitrary WordPress options.
Problem types
Product status
Any version
Credits
Khaled Alenazi (Nxploited)
WPScan
References
wpscan.com/...rability/88b46752-051b-4468-9e2b-cc81a9ce1075/