CVE-2024-4233: Broken Access Control vulnerability in multiple WordPress plugins by Tyche Softwares
Missing Authorization vulnerability in Tyche Softwares Print Invoice & Delivery Notes for WooCommerce, Tyche Softwares Arconix Shortcodes, Tyche Softwares Arconix FAQ.This issue affects Print Invoice & Delivery Notes for WooCommerce: from n/a through 4.8.1; Arconix Shortcodes: from n/a through 2.1.10; Arconix FAQ: from n/a through 1.9.3.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Tyche Softwares Arconix Shortcodesto a version that resolves this vulnerability.Fixed in 2.1.11 - Upgrade
Upgrade
Tyche Softwares Arconix FAQto a version that resolves this vulnerability.Fixed in 1.9.4 - Upgrade
Upgrade
Tyche Softwares Print Invoice & Delivery Notes for WooCommerceto a version that resolves this vulnerability.Fixed in 4.9.0
Event History
Frequently Asked Questions
What is the severity of CVE-2024-4233?
CVE-2024-4233 is classified as a Missing Authorization vulnerability affecting multiple Tyche Softwares plugins.
What software is affected by CVE-2024-4233?
CVE-2024-4233 affects the Print Invoice & Delivery Notes for WooCommerce up to version 4.8.1, Arconix Shortcodes up to version 2.1.10, and Arconix FAQ up to version 1.9.3.
How do I fix CVE-2024-4233?
To fix CVE-2024-4233, update the affected Tyche Softwares plugins to their latest versions that address this vulnerability.
What types of attacks can exploit CVE-2024-4233?
CVE-2024-4233 can be exploited to perform unauthorized actions on behalf of users due to lacking proper authorization checks.
Is user authentication sufficient to protect against CVE-2024-4233?
No, mere user authentication is not sufficient, as the vulnerability is specifically related to missing authorization checks.