CVE-2024-0702: Oliver POS – A WooCommerce Point of Sale (POS) <= 2.4.2.1 - Missing Authorization
The Oliver POS – A WooCommerce Point of Sale (POS) plugin for WordPress is vulnerable to unauthorized access due to missing capability checks on several functions hooked via AJAX in the includes/class-pos-bridge-install.php file in all versions up to, and including, 2.4.2.1 This makes it possible for authenticated attackers, with subscriber-level access and above, to perform several unauthorized actions like deactivating the plugin, disconnecting the subscription, syncing the status and more.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-0702?
CVE-2024-0702 is classified as a critical vulnerability due to the potential for unauthorized access.
How do I fix CVE-2024-0702?
To fix CVE-2024-0702, update the Oliver POS plugin to version 2.4.1.9 or later to ensure capability checks are implemented.
What versions are affected by CVE-2024-0702?
CVE-2024-0702 affects all versions of Oliver POS up to and including 2.4.1.8.
What kind of attack can exploit CVE-2024-0702?
CVE-2024-0702 can be exploited to perform unauthorized actions via AJAX requests due to missing capability checks.
Is CVE-2024-0702 specific to any platform?
CVE-2024-0702 is specifically related to the Oliver POS WooCommerce Point of Sale plugin for WordPress.