Beta

Report

Japanized For WooCommerce <= 2.6.4 is vulnerable to Multiple Broken Access Control vulnerability

Unauthenticated
Published
2023-11-08

The Japanized For WooCommerce plugin for WordPress is vulnerable to unauthorized access and modification due to missing capability checks on several functions called via REST API function in versions up to, and including, 2.6.4. This makes it possible for unauthenticated attackers to perform a wide variety of actions such as updating the plugin's settings and retrieving information about settings.

CVSS

Score:8.6

Severity:High

Version: 2.6.4

There is a patch available in v2.6.5 and we strongly recommend you update to this version as soon as possible.