First published: Wed May 08 2024(Updated: )
Missing Authorization vulnerability in Tyche Softwares Print Invoice & Delivery Notes for WooCommerce, Tyche Softwares Arconix Shortcodes, Tyche Softwares Arconix FAQ.This issue affects Print Invoice & Delivery Notes for WooCommerce: from n/a through 4.8.1; Arconix Shortcodes: from n/a through 2.1.10; Arconix FAQ: from n/a through 1.9.3.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
Print Invoice & Delivery Notes for WooCommerce | <=4.8.1 | |
WordPress Arconix Shortcodes | <=2.1.10 | |
WordPress Arconix FAQ | <=1.9.3 |
Update Print Invoice & Delivery Notes for WooCommerce to 4.9.0 or a higher version.
Update Arconix Shortcodes to 2.1.11 or a higher version.
Update Arconix FAQ to 1.9.4 or a higher version.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-4233 is classified as a Missing Authorization vulnerability affecting multiple Tyche Softwares plugins.
CVE-2024-4233 affects the Print Invoice & Delivery Notes for WooCommerce up to version 4.8.1, Arconix Shortcodes up to version 2.1.10, and Arconix FAQ up to version 1.9.3.
To fix CVE-2024-4233, update the affected Tyche Softwares plugins to their latest versions that address this vulnerability.
CVE-2024-4233 can be exploited to perform unauthorized actions on behalf of users due to lacking proper authorization checks.
No, mere user authentication is not sufficient, as the vulnerability is specifically related to missing authorization checks.