PT-2024-18223 · WordPress · The Thank You Page Customizer For Woocommerce

Lucio Sá

·

Published

2024-02-26

·

Updated

2025-01-15

·

CVE-2024-1687

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions The Thank You Page Customizer for WooCommerce – Increase Your Sales plugin for WordPress versions up to, and including, 1.1.2
Description The issue is related to a missing capability check on the get text editor content() function, allowing authenticated attackers with subscriber-level access and above to execute arbitrary shortcodes. This makes it possible for attackers to perform unauthorized actions.
Recommendations For versions up to, and including, 1.1.2, consider disabling the get text editor content() function until a patch is available to prevent the execution of arbitrary shortcodes. Restrict access to the shortcode execution feature to minimize the risk of exploitation.

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2024-1687

Affected Products

The Thank You Page Customizer For Woocommerce