CVE-2023-2275

The WooCommerce Multivendor Marketplace – REST API plugin for WordPress is vulnerable to unauthorized access of data and addition of data due to a missing capability check on the 'get_item', 'get_order_notes' and 'add_order_note' functions in versions up to, and including, 1.5.3. This makes it possible for authenticated attackers with subscriber privileges or above, to view the order details and order notes, and add order notes.
Configurations

Configuration 1 (hide)

cpe:2.3:a:wclovers:woocommerce_multivendor_marketplace:*:*:*:*:*:wordpress:*:*

History

15 Jun 2023, 15:31

Type Values Removed Values Added
References (MISC) https://plugins.trac.wordpress.org/changeset/2904331/ - (MISC) https://plugins.trac.wordpress.org/changeset/2904331/ - Patch
References (MISC) https://plugins.trac.wordpress.org/browser/wcfm-marketplace-rest-api/tags/1.5.3/includes/api/class-api-order-controller.php#L151 - (MISC) https://plugins.trac.wordpress.org/browser/wcfm-marketplace-rest-api/tags/1.5.3/includes/api/class-api-order-controller.php#L151 - Patch
References (MISC) https://plugins.trac.wordpress.org/browser/wcfm-marketplace-rest-api/tags/1.5.3/includes/api/class-api-order-controller.php#L167 - (MISC) https://plugins.trac.wordpress.org/browser/wcfm-marketplace-rest-api/tags/1.5.3/includes/api/class-api-order-controller.php#L167 - Patch
References (MISC) https://www.wordfence.com/threat-intel/vulnerabilities/id/b0520601-7e5c-412d-a8da-df1bf8ce28df?source=cve - (MISC) https://www.wordfence.com/threat-intel/vulnerabilities/id/b0520601-7e5c-412d-a8da-df1bf8ce28df?source=cve - Third Party Advisory
References (MISC) https://plugins.trac.wordpress.org/browser/wcfm-marketplace-rest-api/tags/1.5.3/includes/api/class-api-order-controller.php#L175 - (MISC) https://plugins.trac.wordpress.org/browser/wcfm-marketplace-rest-api/tags/1.5.3/includes/api/class-api-order-controller.php#L175 - Patch
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.4
CPE cpe:2.3:a:wclovers:woocommerce_multivendor_marketplace:*:*:*:*:*:wordpress:*:*

09 Jun 2023, 06:16

Type Values Removed Values Added
New CVE

Information

Published : 2023-06-09 06:16

Updated : 2024-02-04 23:37


NVD link : CVE-2023-2275

Mitre link : CVE-2023-2275

CVE.ORG link : CVE-2023-2275


JSON object : View

Products Affected

wclovers

  • woocommerce_multivendor_marketplace
CWE

No CWE.