CVE-2024-30469: WordPress Wholesale For WooCommerce plugin <= 2.3.0 - Unauthenticated Sensitive Data Exposure vulnerability
Published Mar 29, 2024
·Updated
Missing Authorization vulnerability in WPExperts Wholesale For WooCommerce.This issue affects Wholesale For WooCommerce: from n/a through 2.3.0.
Affected Software
2 affected components
Wpexperts Wholesale For WooCommerce<=2.3.0
Wpexperts Wholesale For Woocommerce Wordpress<2.3.1
Remediation
Information
Update to 2.3.1 or a higher version.
Event History
Mar 29, 2024
CVE Published
via MITRE·03:47 PM
Data Sourced
via MITRE·03:47 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·04:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-30469?
CVE-2024-30469 is considered a medium severity vulnerability due to its impact on sensitive data exposure.
2
How do I fix CVE-2024-30469?
To fix CVE-2024-30469, update the Wholesale For WooCommerce plugin to the latest version beyond 2.3.0.
3
What is the impact of CVE-2024-30469?
CVE-2024-30469 allows unauthorized access to sensitive data, compromising the security of user information.
4
Which versions of WPExperts Wholesale For WooCommerce are affected by CVE-2024-30469?
CVE-2024-30469 affects all versions of WPExperts Wholesale For WooCommerce up to and including 2.3.0.
5
Is there a known exploit for CVE-2024-30469?
Yes, CVE-2024-30469 has potential exploit scenarios due to the missing authorization vulnerability.