CVE-2024-1686: Thank You Page Customizer for WooCommerce – Increase Your Sales <= 1.1.2 - Missing Authorization to Authenticated (Subscriber+) Data Export
The Thank You Page Customizer for WooCommerce – Increase Your Sales plugin for WordPress is vulnerable to missing authorization e in all versions up to, and including, 1.1.2 via the applylayout function due to a missing capability check. This makes it possible for authenticated attackers, with subscriber-level access and above, to retrieve arbitrary order data which may contain PII.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Thank You Page Customizer for WooCommerce – Increase Your Salesto a version that resolves this vulnerability.Fixed in 1.1.2
Event History
Frequently Asked Questions
What is the severity of CVE-2024-1686?
CVE-2024-1686 has a medium severity rating due to its potential for unauthorized access by authenticated users.
How do I fix CVE-2024-1686?
To fix CVE-2024-1686, update the Thank You Page Customizer for WooCommerce plugin to version 1.1.3 or later.
Who is affected by CVE-2024-1686?
CVE-2024-1686 affects all versions of the Thank You Page Customizer for WooCommerce plugin up to and including 1.1.2.
What is the impact of CVE-2024-1686?
The impact of CVE-2024-1686 allows authenticated attackers to manipulate layout settings without appropriate authorization.
What should I do if I cannot update my plugin to fix CVE-2024-1686?
If you cannot update the plugin, consider disabling it or implementing other security measures to mitigate potential risks related to CVE-2024-1686.