CVE-2024-0617

The Category Discount Woocommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the wpcd_save_discount() function in all versions up to, and including, 4.12. This makes it possible for unauthenticated attackers to modify product category discounts that could lead to loss of revenue.
Configurations

Configuration 1 (hide)

cpe:2.3:a:quanticedgesolutions:category_discount_woocommerce:*:*:*:*:*:wordpress:*:*

History

02 Feb 2024, 05:07

Type Values Removed Values Added
References () https://plugins.trac.wordpress.org/browser/woo-product-category-discount/trunk/cd-admin.php#L171 - () https://plugins.trac.wordpress.org/browser/woo-product-category-discount/trunk/cd-admin.php#L171 - Product
References () https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3026242%40woo-product-category-discount&new=3026242%40woo-product-category-discount&sfp_email=&sfph_mail= - () https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3026242%40woo-product-category-discount&new=3026242%40woo-product-category-discount&sfp_email=&sfph_mail= - Patch
References () https://www.wordfence.com/threat-intel/vulnerabilities/id/996b44bb-d1e0-4f82-b8ee-a98b0ae994f9?source=cve - () https://www.wordfence.com/threat-intel/vulnerabilities/id/996b44bb-d1e0-4f82-b8ee-a98b0ae994f9?source=cve - Third Party Advisory
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.3
CPE cpe:2.3:a:quanticedgesolutions:category_discount_woocommerce:*:*:*:*:*:wordpress:*:*
CWE CWE-862
First Time Quanticedgesolutions category Discount Woocommerce
Quanticedgesolutions

25 Jan 2024, 02:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-01-25 02:15

Updated : 2024-02-28 20:54


NVD link : CVE-2024-0617

Mitre link : CVE-2024-0617

CVE.ORG link : CVE-2024-0617


JSON object : View

Products Affected

quanticedgesolutions

  • category_discount_woocommerce
CWE
CWE-862

Missing Authorization