Unauthorized Data Modification Vulnerability in WooCommerce Wishlist plugin
CVE-2024-10567

7.5HIGH

Key Information:

Vendor
Wordpress
Vendor
CVE Published:
4 December 2024

Summary

The TI WooCommerce Wishlist plugin for WordPress is susceptible to unauthorized data modification due to an absence of a necessary capability check in the 'wizard' function. This vulnerability affects all versions up to and including version 2.9.1. Attackers can exploit this flaw to create new pages, modify settings of the plugin, and execute limited updates without authentication, posing significant risks to the integrity and security of the website utilizing this plugin.

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

.