CVE-2023-51546
WordPress WooCommerce PDF Invoices, Packing Slips, Delivery Notes and Shipping Labels plugin <= 4.2.1 - Privilege Escalation vulnerability
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Improper Privilege Management vulnerability in WebToffee WooCommerce PDF Invoices, Packing Slips, Delivery Notes and Shipping Labels allows Privilege Escalation.This issue affects WooCommerce PDF Invoices, Packing Slips, Delivery Notes and Shipping Labels: from n/a through 4.2.1.
Una vulnerabilidad de gestiĆ³n de privilegios incorrecta en WebToffee WooCommerce PDF Invoices, Packing Slips, Delivery Notes and Shipping Label permite la escalada de privilegios. Este problema afecta a WooCommerce PDF Invoices, Packing Slips, Delivery Notes and Shipping Labels: desde n/a hasta 4.2.1.
The WooCommerce PDF Invoices, Packing Slips, Delivery Notes and Shipping Labels plugin for WordPress is vulnerable to arbitrary options updates via the JSON import functionality in all versions up to, and including, 4.2.1. This makes it possible for authenticated attackers, with Shop Manager access and above, to update arbitrary site options.
CVSS Scores
SSVC
- Decision:Track*
Timeline
- 2023-12-20 CVE Reserved
- 2023-12-27 CVE Published
- 2024-05-18 EPSS Updated
- 2024-08-02 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-20: Improper Input Validation
- CWE-269: Improper Privilege Management
CAPEC
- CAPEC-233: Privilege Escalation
References (1)
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Print Invoices Packing Slip Labels For Woocommerce Search vendor "Print Invoices Packing Slip Labels For Woocommerce" | Print Invoices Packing Slip Labels For Woocommerce Search vendor "Print Invoices Packing Slip Labels For Woocommerce" for product "Print Invoices Packing Slip Labels For Woocommerce" | >= 0.0.0 <= 4.2.1 Search vendor "Print Invoices Packing Slip Labels For Woocommerce" for product "Print Invoices Packing Slip Labels For Woocommerce" and version " >= 0.0.0 <= 4.2.1" | en |
Affected
|