Product Designer <= 1.0.33 - Missing Authorization to Unauthenticated Arbitrary Attachment Deletion

2024-07-08 19:40
Lucio Sá

Strategic Overview

Status
Patched in 1.0.34
Affected Version<= 1.0.33
CVSS5.3Medium
CVECVE-2024-3608
View all PickPlugins Product Designer for WooCommerce vulnerabilities

Vulnerability Overview

The Product Designer plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the product_designer_ajax_delete_attach_id() function in all versions up to, and including, 1.0.33. This makes it possible for unauthenticated attackers to delete arbitrary attachments. CVE-2024-38726 appears to be a duplicate of this issue.

Technical Analysis

REMEDIATION: Update to version 1.0.34, or a newer patched version --- IDENTIFIER: CWE-862 (Missing Authorization) The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C