Unauthorized Access to Order Fees in WooCommerce Plugin
CVE-2024-1119
5.3MEDIUM
What is CVE-2024-1119?
The Order Tip for WooCommerce plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the export_tips_to_csv() function in all versions up to, and including, 1.3.1. This makes it possible for unauthenticated attackers to export the plugin's order fees.
Affected Version(s)
Order Tip for WooCommerce * <= 1.3.1