Lucene search

K
wpvulndbWpvulndbWPVDB-ID:23A21BF4-0617-4AD5-85F0-8BDFD9B90D4B
HistoryNov 24, 2023 - 12:00 a.m.

WooCommerce Checkout Manager < 7.3.1 - Missing Authorization

2023-11-2400:00:00
wpscan.com
6
wordpress
vulnerability
unauthorized access

AI Score

7.1

Confidence

Low

EPSS

0

Percentile

9.0%

Description The WooCommerce Checkout Manager plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the ajax_order_attachment_upload and ajax_delete_attachment functions hooked via AJAX in versions up to, and including, 7.3.0. This makes it possible for unauthenticated attackers to update arbitrary order attachments and delete them.

AI Score

7.1

Confidence

Low

EPSS

0

Percentile

9.0%

Related for WPVDB-ID:23A21BF4-0617-4AD5-85F0-8BDFD9B90D4B