CVE-2024-3608 – Product Designer <= 1.0.33 - Missing Authorization to Unauthenticated Arbitrary Attachment Deletion
https://notcve.org/view.php?id=CVE-2024-3608
The Product Designer plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the product_designer_ajax_delete_attach_id() function in all versions up to, and including, 1.0.33. This makes it possible for unauthenticated attackers to delete arbitrary attachments. El complemento Product Designer para WordPress es vulnerable a la pérdida no autorizada de datos debido a una falta de verificación de capacidad en la función product_designer_ajax_delete_attach_id() en todas las versiones hasta la 1.0.33 incluida. Esto hace posible que atacantes no autenticados eliminen archivos adjuntos arbitrarios. The Product Designer plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the product_designer_ajax_delete_attach_id() function in all versions up to, and including, 1.0.33. • https://plugins.trac.wordpress.org/browser/product-designer/trunk/includes/designer-function.php#L412 https://www.wordfence.com/threat-intel/vulnerabilities/id/2f127fe5-67b8-40e1-a916-c607410b08b3?source=cve • CWE-862: Missing Authorization •
CVE-2024-31277 – WordPress Product Designer plugin <= 1.0.32 - PHP Object Injection vulnerability
https://notcve.org/view.php?id=CVE-2024-31277
Deserialization of Untrusted Data vulnerability in PickPlugins Product Designer.This issue affects Product Designer: from n/a through 1.0.32. Vulnerabilidad de deserialización de datos no confiables en PickPlugins Product Designer. Este problema afecta a Product Designer: desde n/a hasta 1.0.32. The Product Designer plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.0.32 via deserialization of untrusted input. This makes it possible for unauthenticated attackers to inject a PHP Object. • https://patchstack.com/database/vulnerability/product-designer/wordpress-product-designer-plugin-1-0-32-php-object-injection-vulnerability?_s_id=cve • CWE-502: Deserialization of Untrusted Data •