CVE-2024-3869
16.04.2024, 13:15
The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'woocommerce_json_search_coupons' function . This makes it possible for attackers with subscriber level access to view coupon codes.Enginsight
Vendor | Product | Version |
---|---|---|
cusrev | customer_reviews_for_woocommerce | 𝑥 < 5.47.0 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References