The WooCommerce Smart Coupons plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the woocommerce_coupon_admin_init function in versions up to, and including, 4.6.0. This makes it possible for unauthenticated attackers to send themselves gift certificates of any value, which could be redeemed for products sold on the victim’s storefront.
Metrics
Affected Vendors & Products
References
History
Wed, 16 Oct 2024 18:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Woocommerce
Woocommerce woocommerce Smart Coupons |
|
CPEs | cpe:2.3:a:woocommerce:woocommerce_smart_coupons:*:*:*:*:*:*:*:* | |
Vendors & Products |
Woocommerce
Woocommerce woocommerce Smart Coupons |
|
Metrics |
ssvc
|
Wed, 16 Oct 2024 13:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | The WooCommerce Smart Coupons plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the woocommerce_coupon_admin_init function in versions up to, and including, 4.6.0. This makes it possible for unauthenticated attackers to send themselves gift certificates of any value, which could be redeemed for products sold on the victim’s storefront. | |
Title | WooCommerce Smart Coupons <= 4.6.0 - Unauthenticated Coupon Creation | |
Weaknesses | CWE-285 | |
References |
| |
Metrics |
cvssV3_1
|
MITRE
Status: PUBLISHED
Assigner: Wordfence
Published: 2024-10-16T12:45:52.256Z
Updated: 2024-10-16T17:25:40.373Z
Reserved: 2024-10-15T18:51:09.627Z
Link: CVE-2020-36841
Vulnrichment
Updated: 2024-10-16T17:07:20.683Z
NVD
Status : Awaiting Analysis
Published: 2024-10-16T13:15:11.733
Modified: 2024-10-16T16:38:14.557
Link: CVE-2020-36841
Redhat
No data.