CVE-2024-1756
Last modified
CVE-2024-1756 is a medium-severity vulnerability rated 6.5/10 on the CVSS scale. The WooCommerce Customers Manager WordPress plugin before 29.8 does not have authorisation and CSRF in an AJAX action, allowing any authenticated users, such as subscriber, to call it and retrieve the list of customer email addresses along with their id, first name and last name. EPSS estimates a 0.32% chance of exploitation in the next 30 days.
Description
The WooCommerce Customers Manager WordPress plugin before 29.8 does not have authorisation and CSRF in an AJAX action, allowing any authenticated users, such as subscriber, to call it and retrieve the list of customer email addresses along with their id, first name and last name
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Vanquish | Woocommerce Customers Manager | < 29.8 |
References
- https://wpscan.com/vulnerability/0baedd8d-2bbe-4091-bec4-f99e25d7290d/Exploit, Third Party Advisory
- https://wpscan.com/vulnerability/0baedd8d-2bbe-4091-bec4-f99e25d7290d/Exploit, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2024-1756?
How severe is CVE-2024-1756?
How do I fix CVE-2024-1756?
Are you affected by CVE-2024-1756?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
