PT-2024-27840 · Woocommerce · Woocommerce Openpos
Dave Jong
·
Published
2024-08-13
·
Updated
2024-08-17
·
CVE-2024-37935
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
WooCommerce OpenPos versions through 6.4.4
Description
The issue is related to a Missing Authorization vulnerability, which allows accessing functionality not properly constrained by ACLs. This could lead to unauthorized access.
Recommendations
For versions through 6.4.4, patch immediately and review permissions to minimize the risk of exploitation.
Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Woocommerce Openpos