CVE-2024-0617

The Category Discount Woocommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the wpcd_save_discount() function in all versions up to, and including, 4.12. This makes it possible for unauthenticated attackers to modify product category discounts that could lead to loss of revenue.
Configurations

Configuration 1 (hide)

cpe:2.3:a:quanticedgesolutions:category_discount_woocommerce:*:*:*:*:*:wordpress:*:*

History

25 Jan 2024, 02:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-01-25 02:15

Updated : 2024-02-02 05:07


NVD link : CVE-2024-0617

Mitre link : CVE-2024-0617

CVE.ORG link : CVE-2024-0617


JSON object : View

Products Affected

quanticedgesolutions

  • category_discount_woocommerce
CWE
CWE-862

Missing Authorization