CVE-2024-0797

The Active Products Tables for WooCommerce. Professional products tables for WooCommerce store plugin for WordPress is vulnerable to unauthorized access of functionality due to a missing capability check on several functions in all versions up to, and including, 1.0.6.1. This makes it possible for subscribers and higher to execute functions intended for admin use.
Configurations

Configuration 1 (hide)

cpe:2.3:a:pluginus:woot:*:*:*:*:*:wordpress:*:*

History

13 Feb 2024, 19:40

Type Values Removed Values Added
First Time Pluginus
Pluginus woot
CPE cpe:2.3:a:pluginus:woot:*:*:*:*:*:wordpress:*:*
CWE CWE-862
References () https://plugins.trac.wordpress.org/changeset/3029488/profit-products-tables-for-woocommerce/trunk?contextall=1&old=3005088&old_path=%2Fprofit-products-tables-for-woocommerce%2Ftrunk - () https://plugins.trac.wordpress.org/changeset/3029488/profit-products-tables-for-woocommerce/trunk?contextall=1&old=3005088&old_path=%2Fprofit-products-tables-for-woocommerce%2Ftrunk - Patch
References () https://www.wordfence.com/threat-intel/vulnerabilities/id/0a94841f-b1dd-44f4-b7a1-65a9fdf7b18d?source=cve - () https://www.wordfence.com/threat-intel/vulnerabilities/id/0a94841f-b1dd-44f4-b7a1-65a9fdf7b18d?source=cve - Third Party Advisory
Summary
  • (es) El complemento Active Products Tables for WooCommerce. Professional products tables para WordPress son vulnerables al acceso no autorizado a la funcionalidad debido a una falta de verificación de capacidad en varias funciones en todas las versiones hasta la 1.0.6.1 incluida. Esto hace posible que los suscriptores y superiores ejecuten funciones destinadas al uso administrativo.

05 Feb 2024, 22:16

Type Values Removed Values Added
New CVE

Information

Published : 2024-02-05 22:16

Updated : 2024-02-13 19:40


NVD link : CVE-2024-0797

Mitre link : CVE-2024-0797

CVE.ORG link : CVE-2024-0797


JSON object : View

Products Affected

pluginus

  • woot
CWE
CWE-862

Missing Authorization