CVE-2024-3869: Customer Reviews for WooCommerce <= 5.46.0 - Missing Authorization to Authenticated (Subscriber+) Coupon Search
The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'woocommercejsonsearchcoupons' function . This makes it possible for attackers with subscriber level access to view coupon codes.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2024-3869?
CVE-2024-3869 is considered a medium severity vulnerability due to unauthorized data access risks.
How do I fix CVE-2024-3869?
To fix CVE-2024-3869, update the Customer Reviews for WooCommerce plugin to version 5.47.0 or later.
Who is affected by CVE-2024-3869?
Users of the Customer Reviews for WooCommerce plugin version prior to 5.47.0 on their WordPress sites are affected by CVE-2024-3869.
What type of data is exposed by CVE-2024-3869?
CVE-2024-3869 exposes coupon codes to authenticated users with subscriber level access.
What functionality is compromised by CVE-2024-3869?
CVE-2024-3869 compromises the 'woocommerce_json_search_coupons' function by lacking necessary capability checks.