PT-2024-23929 · Zorem · Advanced Local Pickup For Woocommerce

Majed Refaea

·

Published

2024-06-09

·

Updated

2024-06-13

·

CVE-2024-31283

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Advanced Local Pickup for WooCommerce versions 1.6.2 and earlier
Description The issue is related to a Missing Authorization vulnerability in the zorem Advanced Local Pickup for WooCommerce. This vulnerability allows unauthorized access.
Recommendations For versions 1.6.2 and earlier, update to a version later than 1.6.2 to resolve the issue. At the moment, there is no information about other mitigation measures.

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-31283

Affected Products

Advanced Local Pickup For Woocommerce