CyberRota Analysis
This is a high severity vulnerability with a CVSS score of 7.5. It affects WordPress.
CVE
CVE-2019-11807
Severity
HIGH
CVSS
7.5
EPSS
1.47%
WordPress
Original NVD Description
The WooCommerce Checkout Manager plugin before 4.3 for WordPress allows media deletion via the wp-admin/admin-ajax.php?action=update_attachment_wccm wccm_default_keys_load parameter because of a nopriv_ registration and a lack of capabilities checks.
Related CVEs
Other vulnerabilities affecting the same vendor(s)