CVE-2024-3609: ReviewX – Multi-criteria Rating & Reviews for WooCommerce <= 1.6.27 - Missing Authorization
The ReviewX – Multi-criteria Rating & Reviews for WooCommerce plugin for WordPress is vulnerable to unauthorized deletion of data due to a missing capability check on the reviewxremoveguestimage function in all versions up to, and including, 1.6.27. This makes it possible for authenticated attackers, with subscriber access and above, to delete attachments.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2024-3609?
CVE-2024-3609 has been categorized as a high severity vulnerability due to the potential for unauthorized data deletion.
How do I fix CVE-2024-3609?
To fix CVE-2024-3609, upgrade the ReviewX plugin to version 1.6.28 or later.
Which versions are affected by CVE-2024-3609?
CVE-2024-3609 affects all versions of the ReviewX plugin up to and including 1.6.27.
What is the impact of CVE-2024-3609?
The impact of CVE-2024-3609 includes unauthorized deletion of guest images, potentially compromising user data.
Is there any workaround for CVE-2024-3609?
Currently, there are no known workarounds for CVE-2024-3609; updating to the latest version is the recommended solution.