CVE-2024-43131: WordPress Docket (WooCommerce Collections / Wishlist / Watchlist) plugin < 1.7.0 - Unauthenticated Arbitrary Post/Page Deletion vulnerability
Incorrect Authorization vulnerability in WPWeb Docket (WooCommerce Collections / Wishlist / Watchlist) allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Docket (WooCommerce Collections / Wishlist / Watchlist): from n/a before 1.7.0.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-43131?
CVE-2024-43131 has a medium severity level due to its incorrect authorization vulnerability that may allow unauthorized access to features.
How do I fix CVE-2024-43131?
To resolve CVE-2024-43131, update the WPWeb Docket (WooCommerce Collections / Wishlist / Watchlist) plugin to version 1.7.0 or later.
Which versions of WPWeb Docket are affected by CVE-2024-43131?
CVE-2024-43131 affects versions prior to 1.7.0 of the WPWeb Docket (WooCommerce Collections / Wishlist / Watchlist) plugin.
What types of access does CVE-2024-43131 compromise?
CVE-2024-43131 compromises access to functionality that is not properly constrained by access control lists (ACLs), potentially allowing unauthorized users to access sensitive features.
Is there a known exploit for CVE-2024-43131?
As of now, there is no known active exploit for CVE-2024-43131; however, it is advisable to apply the necessary updates to mitigate potential risks.