CVE-2024-1229
14.05.2024, 14:45
The SimpleShop plugin for WordPress is vulnerable to unauthorized disconnection from SimpleShop due to a missing capability check on the maybe_disconnect_simpleshop function in all versions up to, and including, 2.10.2. This makes it possible for unauthenticated attackers to disconnect the SimpleShop.Enginsight
Vendor | Product | Version |
---|---|---|
redbit_sro | simple_shop | 𝑥 ≤ 2.10.2 |
𝑥
= Vulnerable software versions
References