Lucene search

K
wpvulndbWpvulndbWPVDB-ID:FCFC86DC-E891-474E-8231-3B6A1D55951E
HistoryJan 04, 2024 - 12:00 a.m.

WooCommerce Easy Duplicate Product < 0.3.0.8 - Missing Authorization via wedp_duplicate_product_action

2024-01-0400:00:00
wpscan.com
3
wordpress
woocommerce
duplicate product

6.7 Medium

AI Score

Confidence

Low

0.0004 Low

EPSS

Percentile

9.0%

Description The WooCommerce Easy Duplicate Product plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the wedp_duplicate_product_action() function hooked via AJAX in versions up to, and including, 0.3.0.7. This makes it possible for authenticated attackers, with subscriber-level access and above, to duplicate products.

CPENameOperatorVersion
eq0.3.0.8

6.7 Medium

AI Score

Confidence

Low

0.0004 Low

EPSS

Percentile

9.0%

Related for WPVDB-ID:FCFC86DC-E891-474E-8231-3B6A1D55951E