Unauthorized Access Vulnerability in Oliver POS Plugin for WordPress
CVE-2024-0702

7.3HIGH

Key Information:

Vendor
Wordpress
Vendor
CVE Published:
29 February 2024

Summary

The Oliver POS plugin for WooCommerce, a widely used point of sale solution for WordPress, is vulnerable to unauthorized access due to insufficient capability checks in its AJAX functions. This flaw, located in the includes/class-pos-bridge-install.php file, allows authenticated attackers with subscriber-level access or higher to exploit several sensitive functionalities. Actions such as deactivating the plugin, disconnecting user subscriptions, and altering synchronization status can be executed without adequate permissions, potentially compromising overall plugin integrity and user trust.

Affected Version(s)

Oliver POS – A WooCommerce Point of Sale (POS) * <= 2.4.1.8

References

CVSS V3.1

Score:
7.3
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Francesco Carlucci
.