PT-2024-18187 · WordPress · License Manager For Woocommerce
Lucio Sá
·
Published
2024-06-20
·
Updated
2024-07-17
·
CVE-2024-1639
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
License Manager for WooCommerce plugin for WordPress versions up to, and including, 3.0.7
Description
The issue is related to unauthorized access of data due to a missing capability check on the
showLicenseKey() and showAllLicenseKeys() functions. This allows authenticated attackers with admin dashboard access to view arbitrary decrypted license keys. The functions contain a referrer nonce check, but these can be retrieved via the dashboard through the license JS variable.Recommendations
For versions up to, and including, 3.0.7, consider disabling the
showLicenseKey() and showAllLicenseKeys() functions until a patch is available. Restrict access to the License Manager for WooCommerce plugin to minimize the risk of exploitation. Avoid using the license JS variable in the affected dashboard area until the issue is resolved.Fix
Incorrect Authorization
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
License Manager For Woocommerce