PT-2024-16285 · WordPress · Customer Reviews For Woocommerce

Francesco Carlucci

·

Published

2024-02-20

·

Updated

2025-02-05

·

CVE-2024-1044

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Customer Reviews for WooCommerce plugin for WordPress versions up to, and including, 5.38.12
Description The issue allows unauthorized modification of data due to a missing capability check on the submit review function. This enables unauthenticated attackers to submit reviews with arbitrary email addresses, regardless of whether reviews are globally enabled.
Recommendations For versions up to, and including, 5.38.12, update to a version that includes a fix for the missing capability check on the submit review function. As a temporary workaround, consider disabling the submit review function until a patch is available.

Fix

Improper Access Control

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2024-1044

Affected Products

Customer Reviews For Woocommerce