CVE-2024-13652: ECPay Ecommerce for WooCommerce <= 1.1.2411060 - Missing Authorization to Authenticated (Subscriber+) Log Deletion
The ECPay Ecommerce for WooCommerce plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the 'clearecpaydebuglog' AJAX action in all versions up to, and including, 1.1.2411060. This makes it possible for authenticated attackers, with Subscriber-level access and above, to clear the plugin's log files.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-13652?
CVE-2024-13652 has a moderate severity level due to the potential for unauthorized data loss.
How do I fix CVE-2024-13652?
To fix CVE-2024-13652, update the ECPay Ecommerce for WooCommerce plugin to the latest version beyond 1.1.2411060.
Who is affected by CVE-2024-13652?
All users of the ECPay Ecommerce for WooCommerce plugin for WordPress versions up to and including 1.1.2411060 are affected by CVE-2024-13652.
What type of vulnerability is CVE-2024-13652?
CVE-2024-13652 is a security vulnerability that allows unauthorized data loss due to a missing capability check.
Can authenticated users exploit CVE-2024-13652?
Yes, authenticated attackers can exploit CVE-2024-13652 to clear the debug log without proper permissions.