Back to Database
Status published
Medium
CVE-2019-16251
plugin-fw/lib/yit-plugin-panel-wc.php in the YIT Plugin Framework through 3.3.8 for WordPress...
Vulnerability Description
plugin-fw/lib/yit-plugin-panel-wc.php in the YIT Plugin Framework through 3.3.8 for WordPress allows authenticated options changes.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2019-16251
Credits & Attribution
No credits recorded in the NVD database.
References
More from yithemes
View All →CVE-2025-8617
YITH WooCommerce Quick View <= 2.7.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via yith_quick_view Shortcode
Medium
6.4
CVE-2025-5238
YITH WooCommerce Wishlist <= 4.5.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via id Parameter
Medium
6.4
CVE-2025-12777
YITH WooCommerce Wishlist <= 4.10.0 - Unauthenticated Wishlist Token Disclosure to Wishlist Item Deletion
Medium
5.3
CVE-2025-12427
YITH WooCommerce Wishlist <= 4.10.0 - Unauthenticated Insecure Direct Object Reference to Unauthenticated Wishlist Rename
Medium
5.3
CVE-2024-8665
YITH Custom Login <= 1.7.3 - Reflected Cross-Site Scripting
Medium
6.1
Affected Vendor
yithemes
View all reports →Affected Software
yith woocommerce wishlist, yith woocommerce compare, yith woocommerce quick view, yith woocommerce zoom magnifier, yith woocommerce ajax search, yith woocommerce badge management, yith woocommerce brands add-on, yith woocommerce request a quote, yith woocommerce social login, yith woocommerce order tracking, yith woocommerce pdf invoice and shipping list, yith pre-order for woocommerce, yith woocommerce advanced reviews, yith woocommerce product add-ons, yith woocommerce gift cards, yith woocommerce subscription, yith woocommerce affiliates, yith woocommerce cart messages, yith woocommerce product bundles, yith woocommerce frequently bought together, yith woocommerce multi-step checkout, yith color and label variations for woocommerce, yith custom thank you page for woocommerce, yith product size charts for woocommerce, yith woocommerce added to cart popup, yith woocommerce bulk product editing, yith woocommerce stripe, yith woocommerce waiting list, yith woocommerce points and rewards, yith advanced refund system for woocommerce, yith woocommerce authorize.net payment gateway, yith woocommerce best sellers, yith woocommerce mailchimp, yith woocommerce multi vendor, yith woocommerce questions and answers, yith woocommerce recover abandoned cart, yith paypal express checkout for woocommerce, yith desktop notifications for woocommerce
Vulnerable Versions:
0
Timeline
Official Publish:
October 31st, 2019
Last Modified:
August 5th, 2024
Added to House:
July 20th, 2026
CVSS Vectors
V3:
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.