CVE-2024-1954: Oliver POS – A WooCommerce Point of Sale (POS) <= 2.4.1.8 - Cross-Site Request Forgery
The Oliver POS – A WooCommerce Point of Sale (POS) plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.4.1.8. This is due to missing or incorrect nonce validation in the includes/class-pos-bridge-install.php file. This makes it possible for unauthenticated attackers to perform several unauthorized actions like deactivating the plugin, disconnecting the subscription, syncing the status and more via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2024-1954?
CVE-2024-1954 is classified as a high severity vulnerability due to its potential for exploitation via Cross-Site Request Forgery.
How do I fix CVE-2024-1954?
To fix CVE-2024-1954, you should update the Oliver POS plugin to version 2.4.1.9 or later where nonce validation issues have been resolved.
What types of attacks can exploit CVE-2024-1954?
CVE-2024-1954 can be exploited through Cross-Site Request Forgery attacks, allowing unauthorized actions to be performed on behalf of the user.
Which versions of Oliver POS are affected by CVE-2024-1954?
CVE-2024-1954 affects all versions of the Oliver POS plugin up to and including version 2.4.1.8.
Is there a workaround for CVE-2024-1954?
No official workarounds have been provided for CVE-2024-1954, so upgrading to the patched version is recommended.