CVE-2024-32520: WordPress WPC Grouped Product for WooCommerce plugin <= 4.4.2 - Broken Access Control vulnerability
Published Apr 17, 2024
·Updated
Missing Authorization vulnerability in WPClever WPC Grouped Product for WooCommerce.This issue affects WPC Grouped Product for WooCommerce: from n/a through 4.4.2.
Affected Software
1 affected component
WPClever WPC Grouped Product for WooCommerce<=4.4.2
Remediation
Information
Update to 4.4.3 or a higher version.
Event History
Apr 17, 2024
CVE Published
via MITRE·07:33 AM
Data Sourced
via MITRE·07:33 AM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·08:15 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-32520?
CVE-2024-32520 is classified as a Missing Authorization vulnerability affecting WPC Grouped Product for WooCommerce.
2
Which versions are affected by CVE-2024-32520?
CVE-2024-32520 affects WPC Grouped Product for WooCommerce from versions n/a up to and including 4.4.2.
3
How do I fix CVE-2024-32520?
To fix CVE-2024-32520, upgrade the WPC Grouped Product for WooCommerce plugin to a version higher than 4.4.2.
4
What impact does CVE-2024-32520 have on my website?
CVE-2024-32520 can allow unauthorized users to access restricted functionalities within WPC Grouped Product for WooCommerce.
5
Is there a known exploit for CVE-2024-32520?
At this time, specific details of an exploit for CVE-2024-32520 have not been made publicly available.