CVE-2024-1310

Severity
4.9MEDIUM
EPSS
0.5%
top 35.38%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 15

Description

The WooCommerce WordPress plugin before 8.6 does not prevent users with at least the contributor role from leaking products they shouldn't have access to. (e.g. private, draft and trashed products)

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:NExploitability: 1.2 | Impact: 3.6

Affected Packages2 packages

CVEListV5unknown/woocommerce< 8.6

🔴Vulnerability Details

2
CVEList
WooCommerce < 8.6 - Contributor+ Private/Draft Products Access2024-04-15
GHSA
GHSA-qrqj-j85r-f7h4: The WooCommerce WordPress plugin before 82024-04-15
CVE-2024-1310 (MEDIUM CVSS 4.9) | The WooCommerce WordPress plugin be | cvebase.io