The MULTIDOTS WooCommerce Category Banner Management plugin 1.1.0 for WordPress has a security issue that allows anyone to change the plugin’s settings without having to log in. All someone needs to do is send a request with something called a “”wbm_save_shop_page_banner_data action””.