Missing Authorization vulnerability in Pricing Deals for WooCommerce
CVE-2023-41240
5.3MEDIUM
Summary
A missing authorization vulnerability exists in the Vark Pricing Deals for WooCommerce plugin. This issue allows attackers to potentially exploit unauthorized access, affecting versions from n/a to 2.0.3.2. Without proper access controls in place, attackers could manipulate pricing deals, leading to unauthorized modifications or data exposure, which could compromise the integrity of WooCommerce transactions. It is vital for users running affected versions to implement necessary security measures and update to the latest versions to ensure protection against potential exploitation.
Affected Version(s)
Pricing Deals for WooCommerce <= 2.0.3.2
References
CVSS V3.1
Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
thiennv (Patchstack Alliance)