CVE-2019-11807 (woocommerce_checkout_manager)

The WooCommerce Checkout Manager plugin before 4.3 for WordPress allows media deletion via the wp-admin/admin-ajax.php?action=update_attachment_wccm wccm_default_keys_load parameter because of a nopriv_ registration and a lack of capabilities checks.
Source: NIST
CVE-2019-11807 (woocommerce_checkout_manager)

Leave a Reply

Your email address will not be published.