CVE Vulnerabilities

CVE-2024-3869

Published: Apr 16, 2024 | Modified: Apr 16, 2024
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the woocommerce_json_search_coupons function . This makes it possible for attackers with subscriber level access to view coupon codes.

References