Access violation vulnerability in Shipmondo – A complete shipping solution for WooCommerce 5.0.3

The Shipmondo plugin for WordPress, which helps with shipping for online stores using WooCommerce, has a security issue that could allow unauthorized access to data. This is because the plugin doesn’t check for the right permissions when using the getPriceRanges() function, in all versions up to 5.0.3. This means that someone who is logged in and has at least customer-level access could potentially export any WordPress options they want.

Detected in:

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.