Description
The WooCommerce Add to Cart Custom Redirect plugin for WordPress is vulnerable to unauthorized modification of data and loss of data due to a missing capability check on the 'wcr_dismiss_admin_notice' function in all versions up to, and including, 1.2.13. This makes it possible for authenticated attackers, with contributor access and above, to update the values of arbitrary site options to 'dismissed'.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-17587 | The WooCommerce Add to Cart Custom Redirect plugin for WordPress is vulnerable to unauthorized modification of data and loss of data due to a missing capability check on the 'wcr_dismiss_admin_notice' function in all versions up to, and including, 1.2.13. This makes it possible for authenticated attackers, with contributor access and above, to update the values of arbitrary site options to 'dismissed'. |
References
History
Wed, 08 Apr 2026 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | WooCommerce Add to Cart Custom Redirect <= 1.2.13 - Authenticated(Contributor+) Missing Authorization to Limited Arbitrary Options Update |
Thu, 26 Feb 2026 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 03 Apr 2025 13:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Renventura
Renventura woocommerce Add To Cart Custom Redirect |
|
| Weaknesses | CWE-862 | |
| CPEs | cpe:2.3:a:renventura:woocommerce_add_to_cart_custom_redirect:*:*:*:*:*:wordpress:*:* | |
| Vendors & Products |
Renventura
Renventura woocommerce Add To Cart Custom Redirect |
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2026-04-08T16:46:11.481Z
Reserved: 2024-02-23T19:33:55.136Z
Link: CVE-2024-1862
Updated: 2024-08-01T18:56:22.261Z
Status : Modified
Published: 2024-03-13T16:15:27.893
Modified: 2026-04-08T18:20:52.770
Link: CVE-2024-1862
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD