PT-2024-15693 · WordPress · Category Discount Woocommerce

Krzysztof Zając

·

Published

2024-01-24

·

Updated

2024-02-02

·

CVE-2024-0617

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Category Discount Woocommerce plugin for WordPress versions up to, and including, 4.12
Description The issue arises from a missing capability check on the wpcd save discount() function, allowing unauthenticated attackers to modify product category discounts. This could lead to loss of revenue.
Recommendations For versions up to, and including, 4.12, consider disabling the wpcd save discount() function until a patch is available to prevent unauthorized modification of product category discounts.

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2024-0617

Affected Products

Category Discount Woocommerce