First published: Sat Nov 16 2024(Updated: )
The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the cancel_import() function in all versions up to, and including, 5.61.0. This makes it possible for authenticated attackers, with Subscriber-level access and above, to cancel and import or check on the status.
Credit: security@wordfence.com
Affected Software | Affected Version | How to fix |
---|---|---|
WP Customer Reviews | <5.61.1 | |
WP Customer Reviews | <=5.61.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-10614 is considered a medium severity vulnerability due to unauthorized access issues.
To fix CVE-2024-10614, update the Customer Reviews for WooCommerce plugin to version 5.61.1 or later.
CVE-2024-10614 affects users of the Customer Reviews for WooCommerce plugin for WordPress, specifically versions up to and including 5.61.0.
CVE-2024-10614 allows authenticated attackers with Subscriber-level access to perform unauthorized actions.
Yes, CVE-2024-10614 is exploitable in any environment using the affected versions of the Customer Reviews for WooCommerce plugin.