Description
The Sharkdropship for AliExpress Dropshipping and Affiliate plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the wads_removeProductFromShop() function in all versions up to, and including, 2.2.4. This makes it possible for unauthenticated attackers to delete arbitrary posts.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-17460 | The Sharkdropship for AliExpress Dropshipping and Affiliate plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the wads_removeProductFromShop() function in all versions up to, and including, 2.2.4. This makes it possible for unauthenticated attackers to delete arbitrary posts. |
References
History
Wed, 08 Apr 2026 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Sharkdropship for AliExpress Dropshipping and Affiliate <= 2.2.4 - Missing Authorization to Unauthenticated Arbitrary Post Deletion | |
| Weaknesses | CWE-862 |
Fri, 27 Feb 2026 03:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Wooproductimporter
Wooproductimporter sharkdropship Dropshipping And Affiliate |
|
| CPEs | cpe:2.3:a:wooproductimporter:sharkdropship_dropshipping_and_affiliate:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Wooproductimporter
Wooproductimporter sharkdropship Dropshipping And Affiliate |
|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2026-04-08T16:50:40.218Z
Reserved: 2024-02-22T01:36:34.407Z
Link: CVE-2024-1732
Updated: 2024-08-01T18:48:21.821Z
Status : Awaiting Analysis
Published: 2024-04-02T10:15:07.900
Modified: 2026-04-08T18:20:47.617
Link: CVE-2024-1732
No data.
OpenCVE Enrichment
Updated: 2025-07-12T15:42:30Z
Weaknesses
EUVD