The TI WooCommerce Wishlist plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'wizard' function in all versions up to, and including, 2.9.1. This makes it possible for unauthenticated attackers to create new pages, modify plugin settings, and perform limited options updates.
                
            Metrics
Affected Vendors & Products
References
        History
                    Wed, 04 Dec 2024 15:15:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| First Time appeared | 
        
        Woocommerce
         Woocommerce woocommerce  | 
|
| CPEs | cpe:2.3:a:woocommerce:woocommerce:*:*:*:*:*:wordpress:*:* | |
| Vendors & Products | 
        
        Woocommerce
         Woocommerce woocommerce  | 
|
| Metrics | 
        
        ssvc
         
  | 
Wed, 04 Dec 2024 08:45:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Description | The TI WooCommerce Wishlist plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'wizard' function in all versions up to, and including, 2.9.1. This makes it possible for unauthenticated attackers to create new pages, modify plugin settings, and perform limited options updates. | |
| Title | TI WooCommerce Wishlist <= 2.9.1 - Missing Authorization to Unauthenticated Plugin Setup Wizard Access | |
| Weaknesses | CWE-862 | |
| References | 
         | |
| Metrics | 
        
        cvssV3_1
         
  | 
Status: PUBLISHED
Assigner: Wordfence
Published: 2024-12-04T08:22:45.515Z
Updated: 2024-12-04T15:01:08.812Z
Reserved: 2024-10-30T20:24:50.743Z
Link: CVE-2024-10567
Updated: 2024-12-04T15:01:01.404Z
Status : Received
Published: 2024-12-04T09:15:04.177
Modified: 2024-12-04T09:15:04.177
Link: CVE-2024-10567
No data.