WooCommerce Customers Manager <= 29.7 - Missing Authorization to Information Exposure

2024-04-02 00:00
Erwan LR

Strategic Overview

Status
Patched in 29.8
Affected Version<= 29.7
CVSS4.3Medium
CVECVE-2024-1756
View all WooCommerce Customers Manager vulnerabilities

Vulnerability Overview

The WooCommerce Customers Manager plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the wccm_get_customers_list AJAX action in all versions up to, and including, 29.7. This makes it possible for authenticated attackers, with subscriber-level access and above, to retrieve a list of customers and their data.

Technical Analysis

REMEDIATION: Update to version 29.8, or a newer patched version --- IDENTIFIER: CWE-200 (Exposure of Sensitive Information to an Unauthorized Actor) The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C