Vulnerabilities > CVE-2021-4376 - Missing Authorization vulnerability in Palscode Woocommerce Multi Currency

047910
CVSS 4.3 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
LOW
Confidentiality impact
NONE
Integrity impact
LOW
Availability impact
NONE
network
low complexity
palscode
CWE-862

Summary

The WooCommerce Multi Currency plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 2.1.17. This makes it possible for authenticated attackers to change the price of a product to an arbitrary value.

Vulnerable Configurations

Part Description Count
Application
Palscode
1

Common Weakness Enumeration (CWE)