PT-2024-18371 · WordPress · Woocommerce Add To Cart Custom Redirect
Lucio Sá
·
Published
2024-03-13
·
Updated
2024-03-13
·
CVE-2024-1862
CVSS v3.1
8.1
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
WooCommerce Add to Cart Custom Redirect plugin for WordPress versions up to, and including, 1.2.13
Description
The issue allows authenticated attackers with contributor access and above to update the values of arbitrary site options to 'dismissed' due to a missing capability check on the
wcr dismiss admin notice function. This can lead to unauthorized modification of data and loss of data.Recommendations
For versions up to, and including, 1.2.13, update to a version higher than 1.2.13 to resolve the issue.
As a temporary workaround, consider restricting access to the
wcr dismiss admin notice function to prevent unauthorized modifications until a patch is available.Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Woocommerce Add To Cart Custom Redirect