The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'woocommerce_json_search_coupons' function . This makes it possible for attackers with subscriber level access to view coupon codes.
History

Wed, 05 Feb 2025 15:15:00 +0000

Type Values Removed Values Added
First Time appeared Cusrev
Cusrev customer Reviews For Woocommerce
Weaknesses CWE-862
CPEs cpe:2.3:a:cusrev:customer_reviews_for_woocommerce:*:*:*:*:*:wordpress:*:*
Vendors & Products Cusrev
Cusrev customer Reviews For Woocommerce

cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2024-08-01T20:26:57.163Z

Reserved: 2024-04-16T00:15:13.946Z

Link: CVE-2024-3869

cve-icon Vulnrichment

Updated: 2024-08-01T20:26:57.163Z

cve-icon NVD

Status : Analyzed

Published: 2024-04-16T13:15:11.737

Modified: 2025-02-05T14:42:53.307

Link: CVE-2024-3869

cve-icon Redhat

No data.