Unauthorized Disconnection of SimpleShop Plugin Due to Missing Capability Check
CVE-2024-1229
5.3MEDIUM
What is CVE-2024-1229?
The SimpleShop plugin for WordPress is vulnerable to unauthorized disconnection from SimpleShop due to a missing capability check on the maybe_disconnect_simpleshop function in all versions up to, and including, 2.10.2. This makes it possible for unauthenticated attackers to disconnect the SimpleShop.
Affected Version(s)
SimpleShop * <= 2.10.2