CVE-2024-10437: WPC Smart Messages for WooCommerce <= 4.2.1 - Missing Authorization to Authenticated (Subscriber+) Message Activation/Deactivation
The WPC Smart Messages for WooCommerce plugin for WordPress is vulnerable to unauthorized Smar Message activation/deactivation due to a missing capability check on the ajaxenable function in all versions up to, and including, 4.2.1. This makes it possible for authenticated attackers, with Subscriber-level access and above, to activate or deactivate smart messages.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-10437?
CVE-2024-10437 has a moderate severity rating due to the potential for unauthorized activation or deactivation of Smart Messages.
How do I fix CVE-2024-10437?
To fix CVE-2024-10437, update the WPC Smart Messages for WooCommerce plugin to version 4.2.2 or later.
Who is affected by CVE-2024-10437?
CVE-2024-10437 affects all versions of the WPC Smart Messages for WooCommerce plugin up to and including version 4.2.1.
What kind of attack can exploit CVE-2024-10437?
CVE-2024-10437 can be exploited by authenticated attackers to enable or disable Smart Messages without proper permissions.
Is there a patch available for CVE-2024-10437?
Yes, a patch is available in version 4.2.2 and later of the WPC Smart Messages for WooCommerce plugin.