The EU/UK VAT Manager for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the alg_wc_eu_vat_exempt_vat_from_admin() function in all versions up to, and including, 2.12.12. This makes it possible for unauthenticated attackers to update the VAT status for any order.
Metrics
Affected Vendors & Products
References
History
Thu, 03 Oct 2024 17:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Wpfactory eu\/uk Vat Manager For Woocommerce
|
|
CPEs | cpe:2.3:a:wpfactory:eu\/uk_vat_manager_for_woocommerce:*:*:*:*:*:wordpress:*:* | |
Vendors & Products |
Wpfactory eu\/uk Vat Manager For Woocommerce
|
Mon, 30 Sep 2024 16:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Wpfactory
Wpfactory eu\/uk Vat Manager |
|
CPEs | cpe:2.3:a:wpfactory:eu\/uk_vat_manager:*:*:*:*:*:*:*:* | |
Vendors & Products |
Wpfactory
Wpfactory eu\/uk Vat Manager |
|
Metrics |
ssvc
|
Sat, 28 Sep 2024 02:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | The EU/UK VAT Manager for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the alg_wc_eu_vat_exempt_vat_from_admin() function in all versions up to, and including, 2.12.12. This makes it possible for unauthenticated attackers to update the VAT status for any order. | |
Title | EU/UK VAT Manager for WooCommerce <= 2.12.12 - Missing Authorization | |
Weaknesses | CWE-862 | |
References |
| |
Metrics |
cvssV3_1
|
MITRE
Status: PUBLISHED
Assigner: Wordfence
Published: 2024-09-28T02:04:29.505Z
Updated: 2024-09-30T15:45:18.049Z
Reserved: 2024-09-25T20:38:53.861Z
Link: CVE-2024-9189
Vulnrichment
Updated: 2024-09-30T15:45:00.455Z
NVD
Status : Analyzed
Published: 2024-09-28T02:15:10.860
Modified: 2024-10-03T17:26:19.397
Link: CVE-2024-9189
Redhat
No data.