CVE-2024-1310: WooCommerce < 8.6 - Contributor+ Private/Draft Products Access
Published Apr 15, 2024
·Updated
The WooCommerce WordPress plugin before 8.6 does not prevent users with at least the contributor role from leaking products they shouldn't have access to. (e.g. private, draft and trashed products)
Affected Software
2 affected components
Automattic WooCommerce<8.6
Automattic Woocommerce Wordpress<8.6.0
Event History
Apr 15, 2024
CVE Published
via MITRE·05:00 AM
Data Sourced
via MITRE·05:00 AM
DescriptionWeakness
Data Sourced
via NVD·05:15 AM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-1310?
CVE-2024-1310 has been classified as a medium severity vulnerability.
2
How do I fix CVE-2024-1310?
To fix CVE-2024-1310, upgrade the WooCommerce plugin to version 8.6 or later.
3
What types of products can be leaked due to CVE-2024-1310?
Due to CVE-2024-1310, users may leak access to private, draft, and trashed products.
4
Which user roles are affected by CVE-2024-1310?
CVE-2024-1310 affects users with at least the contributor role in WooCommerce.
5
What versions of WooCommerce are affected by CVE-2024-1310?
CVE-2024-1310 affects WooCommerce versions prior to 8.6.