CVE-2024-9189

The EU/UK VAT Manager for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the alg_wc_eu_vat_exempt_vat_from_admin() function in all versions up to, and including, 2.12.12. This makes it possible for unauthenticated attackers to update the VAT status for any order.
Configurations

Configuration 1 (hide)

cpe:2.3:a:wpfactory:eu\/uk_vat_manager_for_woocommerce:*:*:*:*:*:wordpress:*:*

History

03 Oct 2024, 17:26

Type Values Removed Values Added
CPE cpe:2.3:a:wpfactory:eu\/uk_vat_manager_for_woocommerce:*:*:*:*:*:wordpress:*:*
First Time Wpfactory eu\/uk Vat Manager For Woocommerce
Wpfactory
References () https://plugins.trac.wordpress.org/browser/eu-vat-for-woocommerce/tags/2.12.12/includes/class-alg-wc-eu-vat-ajax.php#L285 - () https://plugins.trac.wordpress.org/browser/eu-vat-for-woocommerce/tags/2.12.12/includes/class-alg-wc-eu-vat-ajax.php#L285 - Product
References () https://plugins.trac.wordpress.org/changeset/3158296/ - () https://plugins.trac.wordpress.org/changeset/3158296/ - Patch
References () https://www.wordfence.com/threat-intel/vulnerabilities/id/c6db680e-1fd4-420c-98f4-2b6dc5cf6781?source=cve - () https://www.wordfence.com/threat-intel/vulnerabilities/id/c6db680e-1fd4-420c-98f4-2b6dc5cf6781?source=cve - Third Party Advisory

30 Sep 2024, 12:45

Type Values Removed Values Added
Summary
  • (es) El complemento EU/UK VAT Manager for WooCommerce para WordPress es vulnerable a la modificación no autorizada de datos debido a una falta de comprobación de capacidad en la función alg_wc_eu_vat_exempt_vat_from_admin() en todas las versiones hasta la 2.12.12 incluida. Esto permite que atacantes no autenticados actualicen el estado del IVA de cualquier pedido.

28 Sep 2024, 02:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-09-28 02:15

Updated : 2024-10-03 17:26


NVD link : CVE-2024-9189

Mitre link : CVE-2024-9189

CVE.ORG link : CVE-2024-9189


JSON object : View

Products Affected

wpfactory

  • eu\/uk_vat_manager_for_woocommerce
CWE
CWE-862

Missing Authorization