The WooCommerce Report plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.5.1. This is due to missing or incorrect nonce validation on the settings update functionality. This makes it possible for unauthenticated attackers to update arbitrary options that can be leveraged for privilege escalation via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
Metrics
Affected Vendors & Products
References
History
Thu, 07 Nov 2024 17:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Ithemelandco
Ithemelandco woocommerce Report |
|
CPEs | cpe:2.3:a:ithemelandco:woocommerce_report:*:*:*:*:*:wordpress:*:* | |
Vendors & Products |
Ithemelandco
Ithemelandco woocommerce Report |
Tue, 05 Nov 2024 15:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Tue, 05 Nov 2024 08:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | The WooCommerce Report plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.5.1. This is due to missing or incorrect nonce validation on the settings update functionality. This makes it possible for unauthenticated attackers to update arbitrary options that can be leveraged for privilege escalation via a forged request granted they can trick a site administrator into performing an action such as clicking on a link. | |
Title | WooCommerce Report <= 1.5.1 - Cross-Site Request Forgery to Arbitrary Options Update | |
Weaknesses | CWE-352 | |
References |
|
|
Metrics |
cvssV3_1
|
MITRE
Status: PUBLISHED
Assigner: Wordfence
Published: 2024-11-05T08:31:37.174Z
Updated: 2024-11-05T14:57:09.524Z
Reserved: 2024-11-01T19:57:49.459Z
Link: CVE-2024-10711
Vulnrichment
Updated: 2024-11-05T14:56:54.548Z
NVD
Status : Analyzed
Published: 2024-11-05T09:15:03.667
Modified: 2024-11-07T17:04:37.663
Link: CVE-2024-10711
Redhat
No data.