CVE-2024-39650: WordPress WooCommerce PDF Vouchers plugin < 4.9.5 - Unauthenticated Multiple Vulnerabilities
Missing Authorization vulnerability in WPWeb Elite WooCommerce PDF Vouchers allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects WooCommerce PDF Vouchers: from n/a through 4.9.4.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-39650?
CVE-2024-39650 is classified as a medium severity vulnerability due to the missing authorization that allows access to restricted functionalities.
How do I fix CVE-2024-39650?
To fix CVE-2024-39650, update the WPWeb Elite WooCommerce PDF Vouchers plugin to version 4.9.5 or later.
What systems are affected by CVE-2024-39650?
CVE-2024-39650 affects WPWeb Elite WooCommerce PDF Vouchers versions up to 4.9.4.
What is the nature of CVE-2024-39650?
CVE-2024-39650 is a missing authorization vulnerability that allows users to access functionalities without proper access control.
Are there any known exploits for CVE-2024-39650?
As of now, there are no publicly known exploits specifically targeting CVE-2024-39650, but it remains a security risk until patched.