Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Eduard Stehlík

#47967of 53,635
5.3Total CVSS
Vulnerabilities · 1
PT-2024-39628
5.3
2024-10-30
WordPress · Get Quote For Woocommerce · CVE-2024-9430
**Name of the Vulnerable Software and Affected Versions** Get Quote For Woocommerce – Request A Quote For Woocommerce plugin for WordPress versions up to, and including, 1.0.0 **Description** The issue is related to unauthorized access of Quote data due to a missing capability check on the `ct tepfw wp loaded` function. This allows unauthenticated attackers to download Quote PDF and CSV documents. **Recommendations** For versions up to, and including, 1.0.0, consider disabling the `ct tepfw wp loaded` function until a patch is available to prevent unauthorized access to Quote data.