CVE-2020-36834
Last modified
CVE-2020-36834 is a medium-severity vulnerability rated 6.3/10 on the CVSS scale. The Discount Rules for WooCommerce plugin for WordPress is vulnerable to missing authorization via several AJAX actions in versions up to, and including, 2.0.2 due to missing capability checks on various functions. This makes it possible for subscriber-level attackers to execute various actions and perform a wide variety of actions such as modifying rules and saving configurations.. EPSS estimates a 0.34% chance of exploitation in the next 30 days.
Description
The Discount Rules for WooCommerce plugin for WordPress is vulnerable to missing authorization via several AJAX actions in versions up to, and including, 2.0.2 due to missing capability checks on various functions. This makes it possible for subscriber-level attackers to execute various actions and perform a wide variety of actions such as modifying rules and saving configurations.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2020-36834?
How severe is CVE-2020-36834?
How do I fix CVE-2020-36834?
Are you affected by CVE-2020-36834?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
