CVE-2024-13511
Variation Swatches for WooCommerce 1.0.8 - 1.3.2 - Cross-Site Request Forgery to Plugin Settings Reset
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
The Variation Swatches for WooCommerce plugin, in all versions starting at 1.0.8 up until 1.3.2, contains a vulnerability due to improper nonce verification in its settings reset functionality. The issue exists in the settings_init() function, which processes a reset action based on specific query parameters in the URL. The related delete_settings() function performs a faulty nonce validation check, making the reset operation insecure and susceptible to unauthorized access.
El complemento Variation Swatches para WooCommerce, en todas las versiones a partir de la 1.0.8 hasta la 1.3.2, contiene una vulnerabilidad debido a una verificación de nonce incorrecta en su función de restablecimiento de configuraciones. El problema existe en la función settings_init(), que procesa una acción de restablecimiento en función de parámetros de consulta específicos en la URL. La función delete_settings() relacionada realiza una verificación de validación de nonce defectuosa, lo que hace que la operación de restablecimiento sea insegura y susceptible a acceso no autorizado.
CVSS Scores
SSVC
- Decision:Track
Timeline
- 2025-01-17 CVE Reserved
- 2025-01-22 CVE Published
- 2025-01-23 CVE Updated
- 2025-04-01 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-352: Cross-Site Request Forgery (CSRF)
CAPEC
References (3)
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Themehunk Search vendor "Themehunk" | Variation Swatches For WooCommerce Search vendor "Themehunk" for product "Variation Swatches For WooCommerce" | >= 1.0.8 <= 1.3.2 Search vendor "Themehunk" for product "Variation Swatches For WooCommerce" and version " >= 1.0.8 <= 1.3.2" | en |
Affected
|