Input validation vulnerability in Advanced Product Fields (Product Addons) for WooCommerce 1.6.17

The plugin called Advanced Product Fields (Product Addons) for WooCommerce on WordPress has a security vulnerability called Cross-Site Request Forgery. This means that in versions up to 1.6.17, there is a problem with verifying a security code called a nonce on the ‘maybe_duplicate’ function. This can allow people who are not logged in to the website to copy and publish groups of product fields, even if they are still in the draft or pending stage. The attacker would need to trick a site administrator into clicking on a link in order for this to work.

Detected in:

Advanced Product Fields (Product Addons) for WooCommerce fixed vulnerable versions: >= * <= 1.6.17

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.