PT-2024-38024 · Woocommerce+1 · Addonify Floating Cart For Woocommerce+1

Lucio Sá

·

Published

2024-08-08

·

Updated

2025-03-01

·

CVE-2024-6987

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Orchid Store theme for WordPress versions up to, and including, 1.5.6
Description The issue is related to a missing capability check on the orchid store activate plugin function, allowing authenticated attackers with Subscriber-level access and above to activate the Addonify Floating Cart For WooCommerce plugin if it is installed. This enables potential unauthorized modification of data.
Recommendations For versions up to, and including, 1.5.6, update the plugin to the latest patched version immediately. As a temporary workaround, consider restricting access to the orchid store activate plugin function until a patch is available.

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2024-6987

Affected Products

Addonify Floating Cart For Woocommerce
Orchid Store