CVE-2024-1120: NextMove Lite – Thank You Page for WooCommerce & Finale Lite – Sales Countdown Timer & Discount for WooCommerce <= 2.17.0 - Missing Authorization to Unauthenticated System Information Disclosure
The NextMove Lite – Thank You Page for WooCommerce and Finale Lite – Sales Countdown Timer & Discount for WooCommerce plugins for WordPress are vulnerable to unauthorized access of data due to a missing capability check on the downloadtoolssettings() function in all versions up to, and including, 2.17.0. This makes it possible for unauthenticated attackers to export system information that can aid attackers in an attack.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2024-1120?
CVE-2024-1120 is classified as a medium severity vulnerability due to unauthorized access of data.
How do I fix CVE-2024-1120?
To fix CVE-2024-1120, you should update both the NextMove Lite – Thank You Page for WooCommerce and Finale Lite – Sales Countdown Timer & Discount for WooCommerce plugins to the latest version.
Which versions are affected by CVE-2024-1120?
CVE-2024-1120 affects all versions of NextMove Lite – Thank You Page for WooCommerce and Finale Lite – Sales Countdown Timer & Discount for WooCommerce up to and including version 2.17.0.
What type of vulnerability is CVE-2024-1120?
CVE-2024-1120 is an unauthorized access vulnerability resulting from a missing capability check.
Are there any known exploits for CVE-2024-1120?
As of now, there are no publicly available exploits for CVE-2024-1120 reported in the wild.