ShadowTrackr

Search the CVE vulnerability database

Look up vulnerabilities by software, product or CVE number.

1 result for “CVE-2020-36696”

CVEPublishedCVSSShadowTrackr CVSSSummary
CVE:
CVE-2020-36696
Published
2023-06-07
CVSS:
7.5
ShadowTrackr CVSS:
6.9
Summary:
The Product Input Fields for WooCommerce plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the handle_downloads() function in versions up to, and including, 1.2.6. This makes it possible for unauthenticated attackers to download files from the vulnerable service.