PT-2024-39628 · WordPress · Get Quote For Woocommerce

Eduard Stehlík

+1

·

Published

2024-10-30

·

Updated

2024-11-01

·

CVE-2024-9430

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Get Quote For Woocommerce – Request A Quote For Woocommerce plugin for WordPress versions up to, and including, 1.0.0
Description The issue is related to unauthorized access of Quote data due to a missing capability check on the ct tepfw wp loaded function. This allows unauthenticated attackers to download Quote PDF and CSV documents.
Recommendations For versions up to, and including, 1.0.0, consider disabling the ct tepfw wp loaded function until a patch is available to prevent unauthorized access to Quote data.

Fix

Missing Authentication

Weakness Enumeration

Related Identifiers

CVE-2024-9430

Affected Products

Get Quote For Woocommerce