CVE-2024-0201
Product Expiry for WooCommerce <= 2.5 - Missing Authorization to Authenticated (Subscriber+) Plugin Settings Update
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
The Product Expiry for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'save_settings' function in versions up to, and including, 2.5. This makes it possible for authenticated attackers, with subscriber-level permissions or above to update plugin settings.
Product Expiry for WooCommerce plugin for WordPress es vulnerable a modificaciones no autorizadas de datos debido a una falta de verificación de capacidad en la función 'save_settings' en versiones hasta la 2.5 inclusive. Esto hace posible que atacantes autenticados, con permisos de nivel de suscriptor o superiores, actualicen la configuración del complemento.
The Product Expiry for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'save_settings' function in versions up to, and including, 2.5. This makes it possible for authenticated attackers, with subscriber-level permissions or above to update plugin settings. CVE-2023-52179 appears to be a duplicate of this issue.
CVSS Scores
SSVC
- Decision:Track
Timeline
- 2024-01-02 CVE Reserved
- 2024-01-02 CVE Published
- 2025-04-15 EPSS Updated
- 2025-04-17 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-862: Missing Authorization
CAPEC
References (3)
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Webcodingplace Search vendor "Webcodingplace" | Product Expiry For Woocommerce Search vendor "Webcodingplace" for product "Product Expiry For Woocommerce" | < 2.6 Search vendor "Webcodingplace" for product "Product Expiry For Woocommerce" and version " < 2.6" | wordpress |
Affected
|