PT-2024-28588 · Unknown · Woocommerce Pdf Vouchers

Dave Jong

·

Published

2024-11-01

·

Updated

2026-01-26

·

CVE-2024-39650

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions WooCommerce PDF Vouchers versions 4.9.4 and earlier
Description The issue is related to a Missing Authorization vulnerability, which allows accessing functionality not properly constrained by ACLs. This enables attackers to bypass capability checks, granting unauthorized access to admin functions.
Recommendations For versions 4.9.4 and earlier, update to version 4.9.5 or higher to resolve the issue. As a temporary workaround, consider restricting access to admin functions to minimize the risk of exploitation.

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2024-39650

Affected Products

Woocommerce Pdf Vouchers