CVE-2019-16251

MEDIUMCVSS 4.3/10EPSS 0.95%

Last modified

CVE-2019-16251 is a medium-severity vulnerability rated 4.3/10 on the CVSS scale. plugin-fw/lib/yit-plugin-panel-wc.php in the YIT Plugin Framework through 3.3.8 for WordPress allows authenticated options changes.. EPSS estimates a 0.95% chance of exploitation in the next 30 days.

Description

plugin-fw/lib/yit-plugin-panel-wc.php in the YIT Plugin Framework through 3.3.8 for WordPress allows authenticated options changes.

Metrics

CVSS 3.1
4.3/10

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N

EPSS Probability
0.95%

56.6th percentile

Probability of exploitation in the next 30 days. Learn more

Affected Software

VendorProductVersions
YithemesYith Woocommerce Wishlist<= 2.2.13
YithemesYith Woocommerce Compare<= 2.3.13
YithemesYith Woocommerce Quick View<= 1.3.13
YithemesYith Woocommerce Zoom Magnifier<= 1.3.11
YithemesYith Woocommerce Ajax Search<= 1.6.9
YithemesYith Woocommerce Badge Management<= 1.3.19
YithemesYith Woocommerce Brands Add-On<= 1.3.6
YithemesYith Woocommerce Request A Quote<= 1.4.7
YithemesYith Woocommerce Social Login<= 1.3.4
YithemesYith Woocommerce Order Tracking<= 1.2.10
YithemesYith Woocommerce Pdf Invoice And Shipping List<= 1.2.12
YithemesYith Pre-Order For Woocommerce<= 1.1.9
YithemesYith Woocommerce Advanced Reviews<= 1.3.9
YithemesYith Woocommerce Product Add-Ons<= 1.5.21
YithemesYith Woocommerce Gift Cards<= 1.3.7
YithemesYith Woocommerce Subscription<= 1.3.4
YithemesYith Woocommerce Affiliates<= 1.6.3
YithemesYith Woocommerce Cart Messages<= 1.4.3
YithemesYith Woocommerce Product Bundles<= 1.1.15
YithemesYith Woocommerce Frequently Bought Together<= 1.2.10
YithemesYith Woocommerce Multi-Step Checkout<= 1.7.4
YithemesYith Color And Label Variations For Woocommerce<= 1.8.11
YithemesYith Custom Thank You Page For Woocommerce<= 1.1.6
YithemesYith Product Size Charts For Woocommerce<= 1.1.1
YithemesYith Woocommerce Added To Cart Popup<= 1.3.11
YithemesYith Woocommerce Bulk Product Editing<= 1.2.13
YithemesYith Woocommerce Stripe<= 2.0.1
YithemesYith Woocommerce Waiting List<= 1.3.9
YithemesYith Woocommerce Points And Rewards<= 1.3.4
YithemesYith Advanced Refund System For Woocommerce<= 1.0.10
YithemesYith Woocommerce Authorize.Net Payment Gateway<= 1.1.12
YithemesYith Woocommerce Best Sellers<= 1.1.11
YithemesYith Woocommerce Mailchimp<= 2.1.3
YithemesYith Woocommerce Multi Vendor<= 3.4.0
YithemesYith Woocommerce Questions And Answers<= 1.1.9
YithemesYith Woocommerce Recover Abandoned Cart<= 1.3.2
YithemesYith Paypal Express Checkout For Woocommerce<= 1.2.5
YithemesYith Desktop Notifications For Woocommerce<= 1.2.7

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2019-16251?
plugin-fw/lib/yit-plugin-panel-wc.php in the YIT Plugin Framework through 3.3.8 for WordPress allows authenticated options changes.
How severe is CVE-2019-16251?
CVE-2019-16251 has a CVSS score of 4.3/10 (MEDIUM severity). The EPSS model estimates a 0.95% probability of exploitation in the next 30 days.
How do I fix CVE-2019-16251?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2019-16251?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST