Описание
The WooCommerce WordPress plugin before 8.6 does not prevent users with at least the contributor role from leaking products they shouldn't have access to. (e.g. private, draft and trashed products)
Ссылки
- ExploitThird Party Advisory
- ExploitThird Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 8.6 (исключая)
cpe:2.3:a:automattic:woocommerce:*:*:*:*:*:wordpress:*:*
EPSS
Процентиль: 51%
0.00279
Низкий
4.9 Medium
CVSS3
Дефекты
NVD-CWE-noinfo
Связанные уязвимости
CVSS3: 4.9
github
почти 2 года назад
The WooCommerce WordPress plugin before 8.6 does not prevent users with at least the contributor role from leaking products they shouldn't have access to. (e.g. private, draft and trashed products)
EPSS
Процентиль: 51%
0.00279
Низкий
4.9 Medium
CVSS3
Дефекты
NVD-CWE-noinfo