The Discount Rules for WooCommerce plugin for WordPress is vulnerable to missing authorization via several AJAX actions in versions up to, and including, 2.0.2 due to missing capability checks on various functions. This makes it possible for subscriber-level attackers to execute various actions and perform a wide variety of actions such as modifying rules and saving configurations.
Metrics
Affected Vendors & Products
References
History
Wed, 16 Oct 2024 20:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Wed, 16 Oct 2024 07:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | The Discount Rules for WooCommerce plugin for WordPress is vulnerable to missing authorization via several AJAX actions in versions up to, and including, 2.0.2 due to missing capability checks on various functions. This makes it possible for subscriber-level attackers to execute various actions and perform a wide variety of actions such as modifying rules and saving configurations. | |
Title | Discount Rules for WooCommerce <= 2.0.2 - Missing Authorization | |
Weaknesses | CWE-862 | |
References |
| |
Metrics |
cvssV3_1
|
MITRE
Status: PUBLISHED
Assigner: Wordfence
Published: 2024-10-16T06:43:27.178Z
Updated: 2024-10-16T19:13:16.958Z
Reserved: 2024-10-15T18:33:04.324Z
Link: CVE-2020-36834
Vulnrichment
Updated: 2024-10-16T19:13:12.892Z
NVD
Status : Awaiting Analysis
Published: 2024-10-16T07:15:08.127
Modified: 2024-10-16T16:38:14.557
Link: CVE-2020-36834
Redhat
No data.