The TI WooCommerce Wishlist plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'wizard' function in all versions up to, and including, 2.9.1. This makes it possible for unauthenticated attackers to create new pages, modify plugin settings, and perform limited options updates.
Metrics
Affected Vendors & Products
Advisories
Source | ID | Title |
---|---|---|
![]() |
EUVD-2024-33510 | The TI WooCommerce Wishlist plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'wizard' function in all versions up to, and including, 2.9.1. This makes it possible for unauthenticated attackers to create new pages, modify plugin settings, and perform limited options updates. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Wed, 04 Dec 2024 15:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Woocommerce
Woocommerce woocommerce |
|
CPEs | cpe:2.3:a:woocommerce:woocommerce:*:*:*:*:*:wordpress:*:* | |
Vendors & Products |
Woocommerce
Woocommerce woocommerce |
|
Metrics |
ssvc
|
Wed, 04 Dec 2024 08:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | The TI WooCommerce Wishlist plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'wizard' function in all versions up to, and including, 2.9.1. This makes it possible for unauthenticated attackers to create new pages, modify plugin settings, and perform limited options updates. | |
Title | TI WooCommerce Wishlist <= 2.9.1 - Missing Authorization to Unauthenticated Plugin Setup Wizard Access | |
Weaknesses | CWE-862 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2024-12-04T15:01:08.812Z
Reserved: 2024-10-30T20:24:50.743Z
Link: CVE-2024-10567

Updated: 2024-12-04T15:01:01.404Z

Status : Received
Published: 2024-12-04T09:15:04.177
Modified: 2024-12-04T09:15:04.177
Link: CVE-2024-10567

No data.

No data.