CVE-2024-12004: WPC Order Notes for WooCommerce <= 1.5.2 - Cross-Site Request Forgery to Reflected Cross-Site Scripting
The WPC Order Notes for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.5.2. This is due to missing or incorrect nonce validation on the ajaxupdateordernote() function. This makes it possible for unauthenticated attackers to inject malicious web scripts via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-12004?
CVE-2024-12004 is considered to be of high severity due to its potential impact on the security of WordPress sites using the WPC Order Notes for WooCommerce plugin.
How do I fix CVE-2024-12004?
To fix CVE-2024-12004, update the WPC Order Notes for WooCommerce plugin to version 1.5.3 or later which addresses the nonce validation issue.
Which versions of the WPC Order Notes for WooCommerce plugin are affected by CVE-2024-12004?
CVE-2024-12004 affects all versions of the WPC Order Notes for WooCommerce plugin up to and including version 1.5.2.
What type of vulnerability is CVE-2024-12004?
CVE-2024-12004 is classified as a Cross-Site Request Forgery (CSRF) vulnerability.
Can CVE-2024-12004 allow unauthorized actions on my website?
Yes, CVE-2024-12004 can potentially allow unauthenticated users to exploit the vulnerability and perform unauthorized actions on the site.