First published: Tue Apr 16 2024(Updated: )
The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'woocommerce_json_search_coupons' function . This makes it possible for attackers with subscriber level access to view coupon codes.
Credit: security@wordfence.com
Affected Software | Affected Version | How to fix |
---|---|---|
WordPress Customer Reviews for WooCommerce Plugin | ||
WordPress | ||
WP Customer Reviews | <5.47.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-3869 is considered a medium severity vulnerability due to unauthorized data access risks.
To fix CVE-2024-3869, update the Customer Reviews for WooCommerce plugin to version 5.47.0 or later.
Users of the Customer Reviews for WooCommerce plugin version prior to 5.47.0 on their WordPress sites are affected by CVE-2024-3869.
CVE-2024-3869 exposes coupon codes to authenticated users with subscriber level access.
CVE-2024-3869 compromises the 'woocommerce_json_search_coupons' function by lacking necessary capability checks.