Description
The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'woocommerce_json_search_coupons' function . This makes it possible for attackers with subscriber level access to view coupon codes.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-32437 | The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'woocommerce_json_search_coupons' function . This makes it possible for attackers with subscriber level access to view coupon codes. |
References
History
Wed, 08 Apr 2026 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Customer Reviews for WooCommerce <= 5.46.0 - Missing Authorization to Authenticated (Subscriber+) Coupon Search |
Thu, 26 Feb 2026 13:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 05 Feb 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Cusrev
Cusrev customer Reviews For Woocommerce |
|
| Weaknesses | CWE-862 | |
| CPEs | cpe:2.3:a:cusrev:customer_reviews_for_woocommerce:*:*:*:*:*:wordpress:*:* | |
| Vendors & Products |
Cusrev
Cusrev customer Reviews For Woocommerce |
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2026-04-08T17:05:14.241Z
Reserved: 2024-04-16T00:15:13.946Z
Link: CVE-2024-3869
Updated: 2024-08-01T20:26:57.163Z
Status : Modified
Published: 2024-04-16T13:15:11.737
Modified: 2026-04-08T18:21:34.867
Link: CVE-2024-3869
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD