WooCommerce PDF Vouchers < 4.9.9 - Authentication Bypass
2024-12-11 00:00
BondsStrategic Overview
StatusPatched in 4.9.9
Affected PluginWooCommerce - PDF Vouchers
Affected Version
< 4.9.9CVSS9.8Critical
CVE
CVE-2024-54383Vulnerability Overview
The WooCommerce - PDF Vouchers plugin for WordPress is vulnerable to authentication bypass in all versions up to 4.9.9 (exclusive). This makes it possible for unauthenticated attackers to log in as other users.
Technical Analysis
REMEDIATION: Update to version 4.9.9, or a newer patched version --- IDENTIFIER: CWE-288 (Authentication Bypass Using an Alternate Path or Channel) The product requires authentication, but the product has an alternate path or channel that does not require authentication.
External References
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C