CVE-2024-0797

The Active Products Tables for WooCommerce. Professional products tables for WooCommerce store plugin for WordPress is vulnerable to unauthorized access of functionality due to a missing capability check on several functions in all versions up to, and including, 1.0.6.1. This makes it possible for subscribers and higher to execute functions intended for admin use.
Configurations

Configuration 1 (hide)

cpe:2.3:a:pluginus:woot:*:*:*:*:*:wordpress:*:*

History

13 Feb 2024, 19:40

Type Values Removed Values Added
CWE CWE-862
First Time Pluginus
Pluginus woot
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 4.3
CPE cpe:2.3:a:pluginus:woot:*:*:*:*:*:wordpress:*:*
References () https://plugins.trac.wordpress.org/changeset/3029488/profit-products-tables-for-woocommerce/trunk?contextall=1&old=3005088&old_path=%2Fprofit-products-tables-for-woocommerce%2Ftrunk - () https://plugins.trac.wordpress.org/changeset/3029488/profit-products-tables-for-woocommerce/trunk?contextall=1&old=3005088&old_path=%2Fprofit-products-tables-for-woocommerce%2Ftrunk - Patch
References () https://www.wordfence.com/threat-intel/vulnerabilities/id/0a94841f-b1dd-44f4-b7a1-65a9fdf7b18d?source=cve - () https://www.wordfence.com/threat-intel/vulnerabilities/id/0a94841f-b1dd-44f4-b7a1-65a9fdf7b18d?source=cve - Third Party Advisory

05 Feb 2024, 22:16

Type Values Removed Values Added
New CVE

Information

Published : 2024-02-05 22:16

Updated : 2024-02-28 20:54


NVD link : CVE-2024-0797

Mitre link : CVE-2024-0797

CVE.ORG link : CVE-2024-0797


JSON object : View

Products Affected

pluginus

  • woot
CWE
CWE-862

Missing Authorization