The WooCommerce WordPress plugin before 8.6 does not prevent users with at least the contributor role from leaking products they shouldn't have access to. (e.g. private, draft and trashed products)
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Wed, 28 May 2025 01:30:00 +0900

Type Values Removed Values Added
First Time appeared Automattic
Automattic woocommerce
Weaknesses NVD-CWE-noinfo
CPEs cpe:2.3:a:automattic:woocommerce:*:*:*:*:*:wordpress:*:*
Vendors & Products Automattic
Automattic woocommerce

Fri, 01 Nov 2024 01:15:00 +0900

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 4.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2024-10-31T15:14:55.332Z

Reserved: 2024-02-07T14:57:33.129Z

Link: CVE-2024-1310

cve-icon Vulnrichment

Updated: 2024-08-01T18:33:25.395Z

cve-icon NVD

Status : Analyzed

Published: 2024-04-15T05:15:14.857

Modified: 2025-05-27T16:13:32.967

Link: CVE-2024-1310

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses