Beta

Report

Instantio <= 3.3.7 is vulnerable to Settings Change vulnerability

Unauthenticated
Published
2024-12-17

The Instantio – WooCommerce Quick Checkout | Direct Checkout, Floating Cart, Side Cart & Popup Cart plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 3.3.7. This makes it possible for unauthenticated attackers to update plugin settings.

CVSS

Score:6.5

Severity:Medium

Version: 3.3.7

There is a patch available in v3.3.8 and we strongly recommend you update to this version as soon as possible.