MEDIUM
Product Sort and Display for WooCommerce <= 2.4.1 - Missing Authorization
Published Apr 2, 2024
6.5
MEDIUMCVSS 3.1
EPSS 0.56%
Description
The Product Sort and Display for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the psad_update_product_cat_custom_meta_ajax function in all versions up to, and including, 2.4.1. This makes it possible for unauthenticated attackers to hide product categories.
Affected products
-
Affected
- ≥ 0, ≤ 2.4.1
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| A3rev | Product Sort and Display for WooCommerce | unaffected | Affected
|
No data.
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (4)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2024-17532 Advisory
- https://plugins.trac.wordpress.org/browser/woocommerce-product-sort-and-display/trunk/classes/class-wc-psad-admin-hook.php#L306
- https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3055823%40woocommerce-product-sort-and-display&new=3055823%40woocommerce-product-sort-and-display&sfp_email=&sfph_mail=
- https://www.wordfence.com/threat-intel/vulnerabilities/id/c8bd778b-1d56-4544-b2c3-a77a7ec05aa4?source=cve
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner Wordfence
Published Apr 2, 2024
Updated Apr 8, 2026
Reserved Feb 22, 2024
Link CVE-2024-1807
CISA Vulnrichment
Updated Jun 4, 2024
Red Hat
No data
GitHub
No data