CVE-2019-16251

Summary

CVECVE-2019-16251
StatePUBLIC
Assigner[email protected]
Source PriorityCVE Program / NVD first with legacy fallback
Published2019-10-31 17:15:00 UTC
Updated2020-08-24 17:37:00 UTC
Descriptionplugin-fw/lib/yit-plugin-panel-wc.php in the YIT Plugin Framework through 3.3.8 for WordPress allows authenticated options changes.

Risk And Classification

Problem Types: NVD-CWE-noinfo

NVD Known Affected Configurations (CPE 2.3)

TypeVendorProductVersionUpdateEditionLanguage
Application Yithemes Yith Advanced Refund System For Woocommerce All All All All
Application Yithemes Yith Color And Label Variations For Woocommerce All All All All
Application Yithemes Yith Custom Thank You Page For Woocommerce All All All All
Application Yithemes Yith Desktop Notifications For Woocommerce All All All All
Application Yithemes Yith Paypal Express Checkout For Woocommerce All All All All
Application Yithemes Yith Pre-order For Woocommerce All All All All
Application Yithemes Yith Product Size Charts For Woocommerce All All All All
Application Yithemes Yith Woocommerce Added To Cart Popup All All All All
Application Yithemes Yith Woocommerce Advanced Reviews All All All All
Application Yithemes Yith Woocommerce Affiliates All All All All
Application Yithemes Yith Woocommerce Ajax Search All All All All
Application Yithemes Yith Woocommerce Authorize.net Payment Gateway All All All All
Application Yithemes Yith Woocommerce Badge Management All All All All
Application Yithemes Yith Woocommerce Best Sellers All All All All
Application Yithemes Yith Woocommerce Brands Add-on All All All All
Application Yithemes Yith Woocommerce Bulk Product Editing All All All All
Application Yithemes Yith Woocommerce Cart Messages All All All All
Application Yithemes Yith Woocommerce Compare All All All All
Application Yithemes Yith Woocommerce Frequently Bought Together All All All All
Application Yithemes Yith Woocommerce Gift Cards All All All All
Application Yithemes Yith Woocommerce Mailchimp All All All All
Application Yithemes Yith Woocommerce Multi-step Checkout All All All All
Application Yithemes Yith Woocommerce Multi Vendor All All All All
Application Yithemes Yith Woocommerce Order Tracking All All All All
Application Yithemes Yith Woocommerce Pdf Invoice And Shipping List All All All All
Application Yithemes Yith Woocommerce Points And Rewards All All All All
Application Yithemes Yith Woocommerce Product Add-ons All All All All
Application Yithemes Yith Woocommerce Product Bundles All All All All
Application Yithemes Yith Woocommerce Questions And Answers All All All All
Application Yithemes Yith Woocommerce Quick View All All All All
Application Yithemes Yith Woocommerce Recover Abandoned Cart All All All All
Application Yithemes Yith Woocommerce Request A Quote All All All All
Application Yithemes Yith Woocommerce Social Login All All All All
Application Yithemes Yith Woocommerce Stripe All All All All
Application Yithemes Yith Woocommerce Subscription All All All All
Application Yithemes Yith Woocommerce Waiting List All All All All
Application Yithemes Yith Woocommerce Wishlist All All All All
Application Yithemes Yith Woocommerce Zoom Magnifier All All All All

References

ReferenceSourceLinkTags
Authenticated settings change vulnerability in YIT Plugin Framework. – NinTechNet MISC blog.nintechnet.com Third Party Advisory
YIT Plugin Framework <= 3.3.8 - Authenticated Plugin's Settings Change MISC wpvulndb.com Third Party Advisory
CVE Program record CVE.ORG www.cve.org canonical
NVD vulnerability detail NVD nvd.nist.gov canonical, analysis
© CVE.report 2026 |

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

CVE.report and Source URL Uptime Status status.cve.report