CVE-2024-1687: Thank You Page Customizer for WooCommerce – Increase Your Sales <= 1.1.2 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Shortcode Execution
The Thank You Page Customizer for WooCommerce – Increase Your Sales plugin for WordPress is vulnerable to unauthorized execution of shortcodes due to a missing capability check on the gettexteditorcontent() function in all versions up to, and including, 1.1.2. This makes it possible for authenticated attackers, with subscriber-level access and above, to execute arbitrary shortcodes.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
plugin/Thank You Page Customizer for WooCommerce – Increase Your Salesto a version that resolves this vulnerability.Fixed in 1.1.2
Event History
Frequently Asked Questions
What is the severity of CVE-2024-1687?
CVE-2024-1687 is considered a medium severity vulnerability due to the potential for unauthorized execution of shortcodes.
How do I fix CVE-2024-1687?
To fix CVE-2024-1687, update the Thank You Page Customizer for WooCommerce plugin to version 1.1.3 or later.
What versions are affected by CVE-2024-1687?
CVE-2024-1687 affects all versions of the Thank You Page Customizer for WooCommerce plugin up to and including version 1.1.2.
What function is vulnerable in CVE-2024-1687?
The vulnerable function in CVE-2024-1687 is get_text_editor_content(), which lacks a proper capability check.
Can CVE-2024-1687 be exploited by unauthenticated users?
Yes, CVE-2024-1687 can potentially be exploited by unauthenticated users due to the absence of necessary capability checks.