CVE-2024-13343: WooCommerce Customers Manager <= 31.3 - Missing Authorization to Authenticated (Subscriber+) Privilege Escalation
The WooCommerce Customers Manager plugin for WordPress is vulnerable to Privilege Escalation due to a missing capability check on the ajaxassignnewroles() function in all versions up to, and including, 31.3. This makes it possible for authenticated attackers, with Subscriber-level access and above, to elevate their privileges to that of an administrator.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-13343?
CVE-2024-13343 is classified as a high severity vulnerability due to its potential for privilege escalation.
How do I fix CVE-2024-13343?
To fix CVE-2024-13343, update the WooCommerce Customers Manager plugin to the latest version beyond 31.3.
Who is affected by CVE-2024-13343?
Authenticated users with Subscriber-level access and above are potentially affected by CVE-2024-13343.
What type of vulnerability is CVE-2024-13343?
CVE-2024-13343 is a Privilege Escalation vulnerability due to a missing capability check.
Which versions of the WooCommerce Customers Manager plugin are impacted by CVE-2024-13343?
All versions of the WooCommerce Customers Manager plugin up to and including version 31.3 are impacted by CVE-2024-13343.