First published: Fri Apr 12 2024(Updated: )
Missing Authorization vulnerability in WooCommerce WooCommerce Shipping Per Product.This issue affects WooCommerce Shipping Per Product: from n/a through 2.5.4.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
WordPress Ship Per Product | <=2.5.4 |
Update to 2.5.5 or a higher version.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-51499 has been classified with a critical severity level due to its missing authorization vulnerability.
To fix CVE-2023-51499, update WooCommerce Shipping Per Product to the latest version beyond 2.5.4.
CVE-2023-51499 could allow unauthorized users to access sensitive functionalities or data related to shipping per product.
Yes, if you are using WooCommerce Shipping Per Product version 2.5.4 or below, your site is vulnerable to CVE-2023-51499.
If you cannot upgrade, consider applying temporary security measures to limit access or consult a security expert until an upgrade is possible.