Description
The Get Quote For Woocommerce – Request A Quote For Woocommerce plugin for WordPress is vulnerable to unauthorized access of Quote data due to a missing capability check on the ct_tepfw_wp_loaded function in all versions up to, and including, 1.0.0. This makes it possible for unauthenticated attackers to download Quote PDF and CSV documents.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-49935 | The Get Quote For Woocommerce – Request A Quote For Woocommerce plugin for WordPress is vulnerable to unauthorized access of Quote data due to a missing capability check on the ct_tepfw_wp_loaded function in all versions up to, and including, 1.0.0. This makes it possible for unauthenticated attackers to download Quote PDF and CSV documents. |
References
History
Thu, 31 Oct 2024 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Wpcloudtechnologies
Wpcloudtechnologies get A Quote For Woocommerce |
|
| CPEs | cpe:2.3:a:wpcloudtechnologies:get_a_quote_for_woocommerce:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Wpcloudtechnologies
Wpcloudtechnologies get A Quote For Woocommerce |
|
| Metrics |
ssvc
|
Thu, 31 Oct 2024 07:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Get Quote For Woocommerce – Request A Quote For Woocommerce plugin for WordPress is vulnerable to unauthorized access of Quote data due to a missing capability check on the ct_tepfw_wp_loaded function in all versions up to, and including, 1.0.0. This makes it possible for unauthenticated attackers to download Quote PDF and CSV documents. | |
| Title | Get Quote For Woocommerce – Request A Quote For Woocommerce <= 1.0.0 - Missing Authorization to Unauthenticated Quote PDF and CSV Download | |
| Weaknesses | CWE-306 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2026-04-08T16:51:21.779Z
Reserved: 2024-10-02T10:43:09.505Z
Link: CVE-2024-9430
Updated: 2024-10-31T14:18:32.650Z
Status : Awaiting Analysis
Published: 2024-10-31T07:15:03.253
Modified: 2024-11-01T12:57:03.417
Link: CVE-2024-9430
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD