CVE-2024-3869
EUVD-2024-3243716.04.2024, 13:15
The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'woocommerce_json_search_coupons' function . This makes it possible for attackers with subscriber level access to view coupon codes.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| cusrev | customer_reviews_for_woocommerce | 𝑥 < 5.47.0 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References