Files
CVEs-PoC/2018/CVE-2018-11579.md
T
2025-09-29 21:09:30 +02:00

791 B

CVE-2018-11579

Description

class-woo-banner-management.php in the MULTIDOTS WooCommerce Category Banner Management plugin 1.1.0 for WordPress has an Unauthenticated Settings Change Vulnerability, related to certain wp_ajax_nopriv_ usage. Anyone can change the plugin's setting by simply sending a request with a wbm_save_shop_page_banner_data action.

POC

Reference

No PoCs from references.

Github