Access violation vulnerability in Product Recommendation Quiz for eCommerce 2.1.0

The Product Recommendation Quiz for eCommerce plugin for WordPress is not secure in versions up to, and including, 2.1.0. Unauthenticated attackers can modify plugin settings without permission via a request to the ‘settoken’ REST API endpoint. This is caused by a missing capability check on the prq_set_token function.

Detected in:

Product Recommendation Quiz for eCommerce fixed vulnerable versions: >= * <= 2.1.0

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.