The WooCommerce Customers Manager WordPress plugin before 30.2 does not have authorisation and CSRF in various AJAX actions, allowing any authenticated users, such as subscriber, to call them and update/delete/create customer metadata, also leading to Stored Cross-Site Scripting due to the lack of escaping of said metadata values.
Project Subscriptions
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Thu, 29 May 2025 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Vanquish
Vanquish woocommerce Customers Manager |
|
| Weaknesses | CWE-352 | |
| CPEs | cpe:2.3:a:vanquish:woocommerce_customers_manager:*:*:*:*:*:wordpress:*:* | |
| Vendors & Products |
Vanquish
Vanquish woocommerce Customers Manager |
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2024-08-01T14:24:07.026Z
Reserved: 2024-02-22T14:14:40.146Z
Link: CVE-2024-1747
Updated: 2024-08-01T14:24:03.894Z
Status : Analyzed
Published: 2024-08-01T06:15:01.980
Modified: 2025-05-29T17:23:24.683
Link: CVE-2024-1747
No data.
OpenCVE Enrichment
No data.
Weaknesses