WooCommerce Product FAQ Plugin Vulnerable to Unauthorized Data Modification
CVE-2024-5669
6.4MEDIUM
What is CVE-2024-5669?
The WooCommerce Accordion FAQ Plugin for WordPress contains a vulnerability that permits unauthorized data modification due to a missing capability check in the 'ffw_activate_template' function. This flaw affects all versions up to and including 1.6.4. Authenticated attackers with Subscriber-level access or higher can exploit this vulnerability to inject cross-site scripting (XSS) payloads that execute when viewing dashboard templates or accessing FAQs. This could compromise the integrity of the website and potentially expose sensitive user data.
References
CVSS V3.1
Score:
6.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed
Timeline
Vulnerability published