The Product Expiry for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'save_settings' function in versions up to, and including, 2.5. This makes it possible for authenticated attackers, with subscriber-level permissions or above to update plugin settings.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published: 2024-01-03T09:31:51.694Z

Updated: 2024-08-01T17:41:16.026Z

Reserved: 2024-01-02T20:37:57.179Z

Link: CVE-2024-0201

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2024-01-03T10:15:09.240

Modified: 2024-01-09T20:17:56.357

Link: CVE-2024-0201

cve-icon Redhat

No data.