Description
WordPress Plugin YITH WooCommerce Questions and Answers is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently modify plugin options. WordPress Plugin YITH WooCommerce Questions and Answers version 1.1.9 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 1.2.0 or latest
References
https://blog.nintechnet.com/authenticated-settings-change-vulnerability-in-yit-plugin-framework/
https://plugins.svn.wordpress.org/yith-woocommerce-questions-and-answers/trunk/readme.txt
Related Vulnerabilities
WordPress Plugin Booster for WooCommerce Security Bypass (5.4.3)
WordPress Plugin Powerplay Gallery 'upload.php' Arbitrary File Upload (3.2)
WordPress Plugin MC4WP:Mailchimp for WordPress Cross-Site Request Forgery (4.8.4)
WebLogic CVE-2021-35620 Vulnerability (CVE-2021-35620)
Internet Information Services Other Vulnerability (CVE-2000-0630)