CVE-2024-1044: Customer Reviews for WooCommerce <= 5.38.10 - Improper Authorization via submit_review
The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'submitreview' function in all versions up to, and including, 5.38.12. This makes it possible for unauthenticated attackers to submit reviews with arbitrary email addresses regardless of whether reviews are globally enabled.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-1044?
CVE-2024-1044 has a high severity as it allows unauthorized data modification by unauthenticated attackers.
How do I fix CVE-2024-1044?
To fix CVE-2024-1044, update the Customer Reviews for WooCommerce plugin to version 5.39.0 or later.
Who is affected by CVE-2024-1044?
CVE-2024-1044 affects all versions of the Customer Reviews for WooCommerce plugin up to and including 5.38.12.
What type of vulnerability is CVE-2024-1044?
CVE-2024-1044 is an unauthorized modification vulnerability due to a missing capability check.
Can I be attacked through CVE-2024-1044?
Yes, CVE-2024-1044 allows unauthenticated attackers to submit malicious reviews if the vulnerability is not patched.