CVE-2023-35876: WordPress WooCommerce Square Plugin <= 3.8.1 is vulnerable to Insecure Direct Object References (IDOR)
Published Dec 20, 2023
·Updated
Authorization Bypass Through User-Controlled Key vulnerability in WooCommerce WooCommerce Square.This issue affects WooCommerce Square: from n/a through 3.8.1.
Affected Software
1 affected component
Automattic Woocommerce Square Wordpress<3.8.2
Remediation
Information
Update to 3.8.2 or a higher version.
Event History
Dec 20, 2023
CVE Published
via MITRE·02:42 PM
Data Sourced
via MITRE·02:42 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2023-35876?
CVE-2023-35876 is classified as a medium severity vulnerability affecting WooCommerce Square.
2
How do I fix CVE-2023-35876?
To fix CVE-2023-35876, upgrade WooCommerce Square to version 3.8.2 or later.
3
What systems are affected by CVE-2023-35876?
CVE-2023-35876 affects WooCommerce Square versions from n/a to 3.8.1.
4
What type of vulnerability is CVE-2023-35876?
CVE-2023-35876 is an authorization bypass through user-controlled key vulnerability.
5
What impact does CVE-2023-35876 have on users?
CVE-2023-35876 could allow unauthorized access to certain functionalities within WooCommerce Square.