The WooCommerce WordPress plugin before 8.6 does not prevent users with at least the contributor role from leaking products they shouldn't have access to. (e.g. private, draft and trashed products)
History

Tue, 27 May 2025 16:30:00 +0000

Type Values Removed Values Added
First Time appeared Automattic
Automattic woocommerce
Weaknesses NVD-CWE-noinfo
CPEs cpe:2.3:a:automattic:woocommerce:*:*:*:*:*:wordpress:*:*
Vendors & Products Automattic
Automattic woocommerce

Thu, 31 Oct 2024 16:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 4.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published: 2024-04-15T05:00:03.811Z

Updated: 2024-10-31T15:14:55.332Z

Reserved: 2024-02-07T14:57:33.129Z

Link: CVE-2024-1310

cve-icon Vulnrichment

Updated: 2024-08-01T18:33:25.395Z

cve-icon NVD

Status : Analyzed

Published: 2024-04-15T05:15:14.857

Modified: 2025-05-27T16:13:32.967

Link: CVE-2024-1310

cve-icon Redhat

No data.