Lucene search

K
cvePatchstackCVE-2024-30469
HistoryMar 29, 2024 - 4:15 p.m.

CVE-2024-30469

2024-03-2916:15:09
CWE-200
Patchstack
web.nvd.nist.gov
30
wpexperts
wholesale
woocommerce
vulnerability
authorization

CVSS3

5.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

AI Score

9.3

Confidence

High

EPSS

0

Percentile

9.0%

Missing Authorization vulnerability in WPExperts Wholesale For WooCommerce.This issue affects Wholesale For WooCommerce: from n/a through 2.3.0.

Affected configurations

Vulners
Vulnrichment
Node
wpexpertslicense_manager_for_woocommerceRange2.3.0wordpress
VendorProductVersionCPE
wpexpertslicense_manager_for_woocommerce*cpe:2.3:a:wpexperts:license_manager_for_woocommerce:*:*:*:*:*:wordpress:*:*

CNA Affected

[
  {
    "defaultStatus": "unaffected",
    "product": "Wholesale For WooCommerce",
    "vendor": "WPExperts",
    "versions": [
      {
        "changes": [
          {
            "at": "2.3.1",
            "status": "unaffected"
          }
        ],
        "lessThanOrEqual": "2.3.0",
        "status": "affected",
        "version": "n/a",
        "versionType": "custom"
      }
    ]
  }
]

CVSS3

5.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

AI Score

9.3

Confidence

High

EPSS

0

Percentile

9.0%