Lucene search

K
wpvulndbWpvulndbWPVDB-ID:716B6DA2-1A9C-4B2B-93F9-85E8CB4CA9E5
HistoryNov 23, 2023 - 12:00 a.m.

Pricing Deals for WooCommerce <= 2.0.3.2 - Missing Authorization via vtprd_ajax_clone_rule

2023-11-2300:00:00
wpscan.com
13
woocommerce
wordpress
vulnerability
authorization
clone rules

AI Score

6.9

Confidence

Low

EPSS

0.001

Percentile

17.6%

Description The Pricing Deals for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data| due to a missing capability check on the ‘vtprd_ajax_clone_rule’ function in versions up to, and including, 2.0.3.2. This makes it possible for unauthenticated attackers to clone rules.

AI Score

6.9

Confidence

Low

EPSS

0.001

Percentile

17.6%

Related for WPVDB-ID:716B6DA2-1A9C-4B2B-93F9-85E8CB4CA9E5