CVE-2024-5641: One Click Order Re-Order <= 1.1.9 - Missing Authorization to Authenticated (Subscriber+) Stored Cross-Site Scripting
The One Click Order Re-Order plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'cedocorsavegeneralsetting' function in all versions up to, and including, 1.1.9. This makes it possible for authenticated attackers, with Subscriber-level access and above, to change the plugin settings, including adding stored cross-site scripting.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
wordpress/one-click-order-re-orderto a version that resolves this vulnerability.Fixed in 1.1.9 - Configuration
Update the plugin so the 'ced_ocor_save_general_setting' function performs a proper authorization/capability check before saving settings.
One Click Order Re-Order (WordPress plugin) Capability check for 'ced_ocor_save_general_setting' = Add a capability check so only authorized users (higher than Subscriber-level) can modify general settings
Event History
Frequently Asked Questions
What is the severity of CVE-2024-5641?
CVE-2024-5641 has been classified as a high severity vulnerability due to the potential for unauthorized data modification.
How do I fix CVE-2024-5641?
To fix CVE-2024-5641, update the One Click Order Re-Order plugin to version 1.1.10 or higher.
Who is affected by CVE-2024-5641?
CVE-2024-5641 affects all versions of the One Click Order Re-Order plugin for WordPress up to and including 1.1.9.
What kind of attacks can exploit CVE-2024-5641?
CVE-2024-5641 can be exploited by authenticated attackers to modify settings without proper authorization.
Is CVE-2024-5641 already patched?
Yes, CVE-2024-5641 has been patched in version 1.1.10 of the One Click Order Re-Order plugin.