CVE-2024-32144: WordPress Welcart e-Commerce plugin <= 2.9.14 - Broken Access Control vulnerability
Published Jun 11, 2024
·Updated
Missing Authorization vulnerability in Welcart Inc. Welcart e-Commerce.This issue affects Welcart e-Commerce: from n/a through 2.9.14.
Affected Software
1 affected component
Welcart Welcart e-Commerce WordPress<2.10.0
Remediation
Information
Update to 2.10.0 or a higher version.
Event History
Jun 11, 2024
CVE Published
via MITRE·03:48 PM
Data Sourced
via MITRE·03:48 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·04:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-32144?
CVE-2024-32144 is classified as a missing authorization vulnerability that could allow unauthorized access to sensitive data.
2
How do I fix CVE-2024-32144?
To fix CVE-2024-32144, upgrade Welcart e-Commerce to version 2.10.0 or later, where the vulnerability has been addressed.
3
What are the potential impacts of CVE-2024-32144?
The potential impacts of CVE-2024-32144 include unauthorized access to user accounts and sensitive transaction data.
4
Which versions of Welcart e-Commerce are affected by CVE-2024-32144?
CVE-2024-32144 affects all versions of Welcart e-Commerce prior to 2.10.0.
5
How can I determine if I am using a vulnerable version of Welcart e-Commerce related to CVE-2024-32144?
You can determine if you are using a vulnerable version by checking the plugin version in your WordPress dashboard against the affected versions.