WPC Frequently Bought Together for WooCommerce <= 7.1.9 - Missing Authorization

Strategic Overview

Status
Patched in 7.2.0
Affected Version<= 7.1.9
CVSS4.3Medium
CVECVE-2024-43312
View all WPC Frequently Bought Together for WooCommerce vulnerabilities

Vulnerability Overview

The WPC Frequently Bought Together for WooCommerce plugin for WordPress is vulnerable to unauthorized access and modification of data due to a missing capability check on the ajax_add_rule, ajax_add_combination, and ajax_search_term functions in versions up to, and including, 7.1.9. This makes it possible for authenticated attackers, with subscriber-level access and above, to add rules and combinations as well as search terms.

Technical Analysis

REMEDIATION: Update to version 7.2.0, or a newer patched version --- IDENTIFIER: CWE-862 (Missing Authorization) The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C