WholesaleX <= 1.3.2 - Unauthenticated Privilege Escalation
2024-03-29 00:00
Rafie MuhammadStrategic Overview
StatusPatched in 1.3.3
Affected Version
<= 1.3.2CVSS6.5Medium
CVE
CVE-2024-30542Vulnerability Overview
The WholesaleX – WooCommerce Wholesale Plugin (Wholesale Prices, Dynamic Pricing, Tiered Pricing) plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.3.2. This makes it possible for unauthenticated attackers to escalate their privileges.
Technical Analysis
REMEDIATION: Update to version 1.3.3, or a newer patched version --- IDENTIFIER: CWE-269 (Improper Privilege Management) The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.
External References
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C