PT-2024-37642 · WordPress · Woocommerce Product Table Lite

Lucio Sá

·

Published

2024-07-27

·

Updated

2024-07-29

·

CVE-2024-6458

CVSS v3.1

6.4

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions WooCommerce Product Table Lite plugin for WordPress versions up to, and including, 3.5.1
Description The issue allows authenticated attackers with subscriber access and above to modify post titles of arbitrary posts due to a missing capability check on the wcpt presets duplicate preset to table function. Additionally, missing sanitization can lead to Stored Cross-Site Scripting when viewed by an admin via the WooCommerce Product Table.
Recommendations For versions up to, and including, 3.5.1, update to a version that includes a fix for the missing capability check on the wcpt presets duplicate preset to table function and addresses the missing sanitization issue to prevent Stored Cross-Site Scripting. As a temporary workaround, consider restricting access to the wcpt presets duplicate preset to table function to prevent unauthorized post title modifications.

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2024-6458

Affected Products

Woocommerce Product Table Lite