CVE-2021-4379
The WooCommerce Multi Currency plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the wmc_bulk_fixed_price function in versions up to, and including, 2.1.17. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to make changes to product prices.
- Affected products
- Woocommerce Multi Currency
- Villatheme Woocommerce Multi Currency
- < 2.1.18
- Fix
- Available
- CVSS 3.1
- 6.5 MEDIUM
- EPSS
- 0.8% (54th percentile)
- Weakness
- CWE-862
- NVD status
- Modified
- Published
- 2023-06-07
CVE-2021-4379 at NVD
2 known exploits for CVE-2021-4379
Proof-of-concept code and exploit modules indexed by Sploitus