PT-2024-16591 · WordPress · Buy One Click Woocommerce Plugin

Incognito

+1

·

Published

2024-11-13

·

Updated

2024-11-13

·

CVE-2024-10852

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Buy one click WooCommerce plugin for WordPress versions up to, and including, 2.2.9
Description The issue arises from a missing capability check on the buy one click export options AJAX action, allowing authenticated attackers with Subscriber-level access and above to export plugin settings. This results in unauthorized access of data.
Recommendations For versions up to, and including, 2.2.9, update to a version higher than 2.2.9 to resolve the issue. As a temporary workaround, consider restricting access to the buy one click export options AJAX action to prevent unauthorized data export.

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2024-10852

Affected Products

Buy One Click Woocommerce Plugin