PT-2024-18272 · WordPress · Woocommerce Customers Manager

Erwan Lr

·

Published

2024-08-01

·

Updated

2025-05-29

·

CVE-2024-1747

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions WooCommerce Customers Manager WordPress plugin versions prior to 30.2
Description The issue concerns a lack of authorization and CSRF protection in various AJAX actions within the plugin, allowing any authenticated user to update, delete, or create customer metadata. This also leads to Stored Cross-Site Scripting due to the lack of escaping of metadata values.
Recommendations For versions prior to 30.2, update to version 30.2 or later to resolve the issue. As a temporary workaround, consider restricting access to the AJAX actions until the update can be applied.

Exploit

Fix

CSRF

Weakness Enumeration

Related Identifiers

CVE-2024-1747

Affected Products

Woocommerce Customers Manager