CVE-2024-1310
15.04.2024, 05:15
The WooCommerce WordPress plugin before 8.6 does not prevent users with at least the contributor role from leaking products they shouldn't have access to. (e.g. private, draft and trashed products)Enginsight
| Vendor | Product | Version |
|---|---|---|
| automattic | woocommerce | 𝑥 < 8.6 |
𝑥
= Vulnerable software versions