Lucene search

K
cveWordfenceCVE-2024-1044
HistoryFeb 29, 2024 - 1:43 a.m.

CVE-2024-1044

2024-02-2901:43:38
Wordfence
web.nvd.nist.gov
52
woocommerce
wordpress
plugin
vulnerability
data modification
authorization
nvd

CVSS3

5.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

AI Score

6.2

Confidence

High

EPSS

0

Percentile

9.0%

The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the ‘submit_review’ function in all versions up to, and including, 5.38.12. This makes it possible for unauthenticated attackers to submit reviews with arbitrary email addresses regardless of whether reviews are globally enabled.

Affected configurations

Vulners
Vulnrichment
Node
ivolecustomer_reviews_for_woocommerceRange5.38.12wordpress
VendorProductVersionCPE
ivolecustomer_reviews_for_woocommerce*cpe:2.3:a:ivole:customer_reviews_for_woocommerce:*:*:*:*:*:wordpress:*:*

CNA Affected

[
  {
    "vendor": "ivole",
    "product": "Customer Reviews for WooCommerce",
    "versions": [
      {
        "version": "*",
        "status": "affected",
        "lessThanOrEqual": "5.38.12",
        "versionType": "semver"
      }
    ],
    "defaultStatus": "unaffected"
  }
]

CVSS3

5.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

AI Score

6.2

Confidence

High

EPSS

0

Percentile

9.0%