PT-2024-38036 · WordPress · Smart Online Order For Clover

Lucio Sá

·

Published

2024-08-20

·

Updated

2024-08-31

·

CVE-2024-7030

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions The Smart Online Order for Clover plugin for WordPress versions up to, and including, 1.5.6
Description The issue allows authenticated attackers with Subscriber-level access and above to update product and category descriptions, category titles and images, and sort order due to a missing capability check on several functions.
Recommendations For versions up to, and including, 1.5.6, update to a version that includes a capability check on all relevant functions to prevent unauthorized modification of data. As a temporary workaround, consider restricting access to the plugin's functionality for users with Subscriber-level access and above until a patch is available.

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2024-7030

Affected Products

Smart Online Order For Clover