CVE-2024-35667: WordPress Shopping Cart & eCommerce Store plugin <= 5.5.19 - Broken Access Control vulnerability
Published Jun 11, 2024
·Updated
Missing Authorization vulnerability in WP EasyCart.This issue affects WP EasyCart: from n/a through 5.5.19.
Affected Software
2 affected components
WP EasyCart WP EasyCart<=5.5.19
WordPress Shopping Cart & eCommerce Store<=5.5.19
Remediation
Information
Update to 5.6.0 or a higher version.
Event History
Jun 11, 2024
CVE Published
via MITRE·02:09 PM
Data Sourced
via MITRE·02:09 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·03:16 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-35667?
CVE-2024-35667 has been classified as a high severity vulnerability due to missing authorization controls.
2
How do I fix CVE-2024-35667?
To fix CVE-2024-35667, users should update WP EasyCart to the latest version, 5.5.20 or higher.
3
What versions are affected by CVE-2024-35667?
CVE-2024-35667 affects WP EasyCart versions from an unspecified release up to and including 5.5.19.
4
What type of vulnerability is CVE-2024-35667?
CVE-2024-35667 is characterized as a missing authorization vulnerability.
5
Can CVE-2024-35667 lead to data exposure?
Yes, CVE-2024-35667 can potentially lead to unauthorized access and data exposure due to insufficient access controls.