PT-2024-17530 · WordPress · Simpleshop

Francesco Carlucci

·

Published

2024-05-09

·

Updated

2024-05-14

·

CVE-2024-1229

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions SimpleShop plugin for WordPress versions prior to 2.10.3
Description The issue arises from a missing capability check on the maybe disconnect simpleshop function, allowing unauthenticated attackers to disconnect SimpleShop.
Recommendations For versions prior to 2.10.3, update to version 2.10.3 or later to resolve the issue.

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2024-1229

Affected Products

Simpleshop