The TI WooCommerce Wishlist plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'wizard' function in all versions up to, and including, 2.9.1. This makes it possible for unauthenticated attackers to create new pages, modify plugin settings, and perform limited options updates.
Metrics
Affected Vendors & Products
References
History
Wed, 04 Dec 2024 15:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Woocommerce
Woocommerce woocommerce |
|
CPEs | cpe:2.3:a:woocommerce:woocommerce:*:*:*:*:*:wordpress:*:* | |
Vendors & Products |
Woocommerce
Woocommerce woocommerce |
|
Metrics |
ssvc
|
Wed, 04 Dec 2024 08:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | The TI WooCommerce Wishlist plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'wizard' function in all versions up to, and including, 2.9.1. This makes it possible for unauthenticated attackers to create new pages, modify plugin settings, and perform limited options updates. | |
Title | TI WooCommerce Wishlist <= 2.9.1 - Missing Authorization to Unauthenticated Plugin Setup Wizard Access | |
Weaknesses | CWE-862 | |
References |
| |
Metrics |
cvssV3_1
|
MITRE
Status: PUBLISHED
Assigner: Wordfence
Published: 2024-12-04T08:22:45.515Z
Updated: 2024-12-04T15:01:08.812Z
Reserved: 2024-10-30T20:24:50.743Z
Link: CVE-2024-10567
Vulnrichment
Updated: 2024-12-04T15:01:01.404Z
NVD
Status : Received
Published: 2024-12-04T09:15:04.177
Modified: 2024-12-04T09:15:04.177
Link: CVE-2024-10567
Redhat
No data.