Lucene search

K
cvePatchstackCVE-2024-35662
HistoryJun 09, 2024 - 7:15 p.m.

CVE-2024-35662

2024-06-0919:15:51
CWE-862
Patchstack
web.nvd.nist.gov
28
cve-2024-35662
andreas sofantzis
simple cod fees
woocommerce
missing authorization
vulnerability

CVSS3

8.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

EPSS

0.001

Percentile

19.3%

Missing Authorization vulnerability in Andreas Sofantzis Simple COD Fees for WooCommerce.This issue affects Simple COD Fees for WooCommerce: from n/a through 2.0.2.

Affected configurations

Nvd
Vulners
Node
83pixelsimple_cod_fees_for_woocommerceRange2.0.2wordpress
VendorProductVersionCPE
83pixelsimple_cod_fees_for_woocommerce*cpe:2.3:a:83pixel:simple_cod_fees_for_woocommerce:*:*:*:*:*:wordpress:*:*

CNA Affected

[
  {
    "collectionURL": "https://wordpress.org/plugins",
    "defaultStatus": "unaffected",
    "packageName": "simple-cod-fee-for-woocommerce",
    "product": "Simple COD Fees for WooCommerce",
    "vendor": "Andreas Sofantzis",
    "versions": [
      {
        "lessThanOrEqual": "2.0.2",
        "status": "affected",
        "version": "n/a",
        "versionType": "custom"
      }
    ]
  }
]

CVSS3

8.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

EPSS

0.001

Percentile

19.3%