CVE-2024-1310
WooCommerce < 8.6 - Contributor+ Private/Draft Products Access
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
The WooCommerce WordPress plugin before 8.6 does not prevent users with at least the contributor role from leaking products they shouldn't have access to. (e.g. private, draft and trashed products)
El complemento WooCommerce WordPress anterior a 8.6 no impide que los usuarios con al menos el rol de colaborador filtren productos a los que no deberÃan tener acceso. (por ejemplo, productos privados, borradores y desechados)
The WooCommerce plugin for WordPress is vulnerable to unauthorized access of data due to insufficient restrictions in the product shortcode in all versions up to, and including, 8.5.2. This makes it possible for authenticated attackers, with contributor-level access and above, to view private and draft products.
CVSS Scores
SSVC
- Decision:Track
Timeline
- 2024-02-07 CVE Reserved
- 2024-03-25 CVE Published
- 2024-04-15 EPSS Updated
- 2024-10-31 CVE Updated
- 2024-10-31 First Exploit
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|---|---|
https://wpscan.com/vulnerability/a7735feb-876e-461c-9a56-ea6067faf277 | 2024-10-31 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Unknown Search vendor "Unknown" | WooCommerce Search vendor "Unknown" for product "WooCommerce" | < 8.6 Search vendor "Unknown" for product "WooCommerce" and version " < 8.6" | en |
Affected
|