PT-2024-18187 · WordPress · License Manager For Woocommerce

Lucio Sá

·

Published

2024-06-20

·

Updated

2024-07-17

·

CVE-2024-1639

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions License Manager for WooCommerce plugin for WordPress versions up to, and including, 3.0.7
Description The issue is related to unauthorized access of data due to a missing capability check on the showLicenseKey() and showAllLicenseKeys() functions. This allows authenticated attackers with admin dashboard access to view arbitrary decrypted license keys. The functions contain a referrer nonce check, but these can be retrieved via the dashboard through the license JS variable.
Recommendations For versions up to, and including, 3.0.7, consider disabling the showLicenseKey() and showAllLicenseKeys() functions until a patch is available. Restrict access to the License Manager for WooCommerce plugin to minimize the risk of exploitation. Avoid using the license JS variable in the affected dashboard area until the issue is resolved.

Fix

Incorrect Authorization

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-1639

Affected Products

License Manager For Woocommerce