CVE-2024-52395: WordPress Floating Buttons for WooCommerce plugin <= 2.8.8 - Broken Access Control vulnerability
Missing Authorization vulnerability in QuantumCloud Floating Buttons for WooCommerce shop-assistant-for-woocommerce-jarvis allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Floating Buttons for WooCommerce: from n/a through <= 2.8.8.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-52395?
The severity of CVE-2024-52395 is classified as medium with a score of 5.3.
What vulnerability does CVE-2024-52395 describe?
CVE-2024-52395 describes a Broken Access Control vulnerability in the QuantumCloud Floating Buttons for WooCommerce plugin.
How do I fix CVE-2024-52395?
To fix CVE-2024-52395, update the QuantumCloud Floating Buttons for WooCommerce plugin to version 2.9.2 or higher.
What is the impact of CVE-2024-52395?
CVE-2024-52395 allows exploitation of incorrectly configured access control security levels, potentially leading to unauthorized access.
Which versions of the plugin are affected by CVE-2024-52395?
CVE-2024-52395 affects Floating Buttons for WooCommerce plugin versions from n/a through 2.8.8.