The AliExpress Dropshipping with AliNext Lite plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on several functions in the ImportAjaxController.php file in all versions up to, and including, 3.3.5. This makes it possible for authenticated attackers, with subscriber-level access and above, to perform several actions like importing and modifying products.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Fri, 20 Sep 2024 00:45:00 +0000

Type Values Removed Values Added
First Time appeared Ali2woo
Ali2woo aliexpress Dropshipping With Alinext
Weaknesses CWE-862
CPEs cpe:2.3:a:ali2woo:aliexpress_dropshipping_with_alinext:*:*:*:*:lite:wordpress:*:*
Vendors & Products Ali2woo
Ali2woo aliexpress Dropshipping With Alinext

cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2024-08-01T20:40:47.189Z

Reserved: 2024-05-02T20:36:43.554Z

Link: CVE-2024-4450

cve-icon Vulnrichment

Updated: 2024-08-01T20:40:47.189Z

cve-icon NVD

Status : Modified

Published: 2024-06-19T04:15:11.497

Modified: 2024-11-21T09:42:51.320

Link: CVE-2024-4450

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.