CVE-2023-27608: WordPress Points and Rewards for WooCommerce plugin <= 1.5.0 - Broken Access Control vulnerability
Missing Authorization vulnerability in WP Swings Points and Rewards for WooCommerce.This issue affects Points and Rewards for WooCommerce: from n/a through 1.5.0.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2023-27608?
CVE-2023-27608 is classified as a missing authorization vulnerability affecting the Points and Rewards for WooCommerce plugin.
How do I fix CVE-2023-27608?
To fix CVE-2023-27608, it is recommended to update the Points and Rewards for WooCommerce plugin to version 1.5.1 or later.
Which versions of Points and Rewards for WooCommerce are affected by CVE-2023-27608?
CVE-2023-27608 affects versions of Points and Rewards for WooCommerce from an unspecified version up to and including 1.5.0.
What are the consequences of CVE-2023-27608?
Exploitation of CVE-2023-27608 may allow unauthorized users to access restricted functionalities within the Points and Rewards for WooCommerce plugin.
Who is the vendor of the affected product in CVE-2023-27608?
The vendor of the affected product in CVE-2023-27608 is WP Swings.