PT-2025-2236 · WordPress · Ecpay Ecommerce For Woocommerce

Incognito

+1

·

Published

2025-01-30

·

Updated

2025-01-30

·

CVE-2024-13652

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions ECPay Ecommerce for WooCommerce plugin for WordPress versions up to, and including, 1.1.2411060
Description The issue is related to a missing capability check on the 'clear ecpay debug log' AJAX action. This allows authenticated attackers with Subscriber-level access and above to clear the plugin's log files, resulting in unauthorized loss of data.
Recommendations For versions up to, and including, 1.1.2411060, as a temporary workaround, consider disabling the clear ecpay debug log AJAX action until a patch is available. Restrict access to the plugin's log files to minimize the risk of exploitation. Update to a version that includes a fix for the missing capability check on the 'clear ecpay debug log' AJAX action.

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2024-13652

Affected Products

Ecpay Ecommerce For Woocommerce