CVE-2023-51497: WordPress WooCommerce Ship to Multiple Addresses plugin <= 3.8.9 - Broken Access Control vulnerability
Published Jun 14, 2024
·Updated
Missing Authorization vulnerability in Woo WooCommerce Ship to Multiple Addresses.This issue affects WooCommerce Ship to Multiple Addresses: from n/a through 3.8.9.
Affected Software
1 affected component
WooCommerce Shipping Multiple Addresses Wordpress<3.8.10
Remediation
Information
Update to 3.8.10 or a higher version.
Event History
Jun 14, 2024
CVE Published
via MITRE·05:33 AM
Data Sourced
via MITRE·05:33 AM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·06:15 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2023-51497?
CVE-2023-51497 is classified as a missing authorization vulnerability, which could allow unauthorized access to sensitive data.
2
How do I fix CVE-2023-51497?
To fix CVE-2023-51497, update the WooCommerce Ship to Multiple Addresses plugin to version 3.8.10 or later.
3
What versions of WooCommerce Ship to Multiple Addresses are affected by CVE-2023-51497?
CVE-2023-51497 affects versions from n/a until 3.8.9 of the WooCommerce Ship to Multiple Addresses plugin.
4
What are the potential impacts of CVE-2023-51497?
The potential impacts of CVE-2023-51497 include unauthorized users accessing or modifying shipment details.
5
Is CVE-2023-51497 part of a larger vulnerability trend in WooCommerce plugins?
Yes, CVE-2023-51497 highlights a trend of authorization issues in various WooCommerce plugins that may expose users to risks.