Unauthorized Access to Quote Data in Woocommerce Request A Quote Plugin
CVE-2024-9430

5.3MEDIUM

Key Information:

Vendor
Wordpress
Vendor
CVE Published:
31 October 2024

Summary

The Get Quote For Woocommerce – Request A Quote For Woocommerce plugin for WordPress is susceptible to unauthorized access of Quote data due to the lack of a capability check on the ct_tepfw_wp_loaded function. This vulnerability enables unauthenticated attackers to gain access to and download sensitive Quote PDF and CSV documents from the affected versions, specifically all releases up to and including 1.0.0. Website administrators should take immediate action to secure their installations and prevent potential data leakage.

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

.