CVE-2024-0870: YITH WooCommerce Gift Cards <= 4.12.0 - Missing Authorization to Unauthenticated WooCommerce Settings Update
The YITH WooCommerce Gift Cards plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'savemailstatus' and 'saveemailsettings' functions in all versions up to, and including, 4.12.0. This makes it possible for unauthenticated attackers to modify WooCommerce settings.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-0870?
CVE-2024-0870 is considered a high-severity vulnerability due to the potential for unauthorized data modification.
How do I fix CVE-2024-0870?
To fix CVE-2024-0870, update the YITH WooCommerce Gift Cards plugin to version 4.12.1 or later.
What is affected by CVE-2024-0870?
CVE-2024-0870 affects all versions of the YITH WooCommerce Gift Cards plugin up to and including 4.12.0.
Can CVE-2024-0870 be exploited remotely?
Yes, CVE-2024-0870 can be exploited remotely due to the lack of adequate capability checks.
What data is vulnerable due to CVE-2024-0870?
CVE-2024-0870 allows for unauthorized modification of email settings and mail status related to gift cards.