PT-2024-18090 · WordPress · Wpify Woo Czech

Francesco Carlucci

·

Published

2024-02-20

·

Updated

2024-03-08

·

CVE-2024-1492

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions WPify Woo Czech plugin versions up to, and including, 4.0.8
Description The issue allows unauthorized access to data due to a missing capability check on the maybe send to packeta function. This makes it possible for unauthenticated attackers to obtain shipping details for orders as long as the order number is known.
Recommendations For WPify Woo Czech plugin versions up to, and including, 4.0.8, update to a version higher than 4.0.8 to resolve the issue. As a temporary workaround, consider disabling the maybe send to packeta function until a patch is available.

Fix

Improper Access Control

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2024-1492

Affected Products

Wpify Woo Czech