PT-2024-18279 · WordPress · Woocommerce Customers Manager

Erwan Lr

·

Published

2024-04-24

·

Updated

2025-05-07

·

CVE-2024-1756

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions WooCommerce Customers Manager WordPress plugin versions prior to 29.8
Description The issue concerns a lack of authorization and CSRF protection in an AJAX action, allowing any authenticated user to retrieve a list of customer email addresses along with their id, first name, and last name.
Recommendations For versions prior to 29.8, update to version 29.8 or later to resolve the issue. As a temporary workaround, consider restricting access to the AJAX action until the update is applied.

Exploit

Fix

CSRF

Weakness Enumeration

Related Identifiers

CVE-2024-1756

Affected Products

Woocommerce Customers Manager