MEDIUM
ECPay Ecommerce for WooCommerce <= 1.1.2411060 - Missing Authorization to Authenticated (Subscriber+) Log Deletion
Published Jan 30, 2025
4.3
MEDIUMCVSS 3.1
EPSS 0.30%
Description
The ECPay Ecommerce for WooCommerce plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the 'clear_ecpay_debug_log' AJAX action in all versions up to, and including, 1.1.2411060. This makes it possible for authenticated attackers, with Subscriber-level access and above, to clear the plugin's log files.
Affected products
-
Affected
- ≤ 1.1.2411060
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| Ecpaytechsupport | ECPay Ecommerce for WooCommerce | unaffected | Affected
|
- ≤ 1.1.2411060
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (4)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2024-51705 Advisory
- https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3235861%40ecpay-ecommerce-for-woocommerce&new=3235861%40ecpay-ecommerce-for-woocommerce&sfp_email=&sfph_mail=
- https://wordpress.org/plugins/ecpay-ecommerce-for-woocommerce/ Product
- https://www.wordfence.com/threat-intel/vulnerabilities/id/5ae08e0b-ea17-46c1-aad3-4ecea69c1bdc?source=cve Third Party Advisory
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner Wordfence
Published Jan 30, 2025
Updated Apr 8, 2026
Reserved Jan 23, 2025
Link CVE-2024-13652
CISA Vulnrichment
Updated Jan 30, 2025
Red Hat
No data
GitHub
No data