First published: Tue Apr 16 2024(Updated: )
The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to unauthorized email sending due to a missing capability check on the send_test_email() function in all versions up to, and including, 5.46.0. This makes it possible for authenticated attackers, with subscriber-level access and above, to send arbitrary test emails.
Credit: security@wordfence.com
Affected Software | Affected Version | How to fix |
---|---|---|
WordPress Customer Reviews for WooCommerce Plugin | <=5.46.0 | |
WP Customer Reviews | <5.47.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-3243 is considered a moderate severity vulnerability due to its potential for unauthorized email sending.
To fix CVE-2024-3243, update the Customer Reviews for WooCommerce plugin to version 5.47.0 or later.
CVE-2024-3243 affects all users of the Customer Reviews for WooCommerce plugin for WordPress versions up to and including 5.46.0.
The impact of CVE-2024-3243 is that authenticated attackers with subscriber-level access can send unauthorized emails.
A temporary workaround for CVE-2024-3243 is to restrict subscriber-level access or disable the plugin until an update is applied.