CVE-2024-0683

The Bulgarisation for WooCommerce plugin for WordPress is vulnerable to unauthorized access due to missing capability checks on several functions in all versions up to, and including, 3.0.14. This makes it possible for unauthenticated and authenticated attackers, with subscriber-level access and above, to generate and delete labels.
Configurations

Configuration 1 (hide)

cpe:2.3:a:autopolis:bulgarisation_for_woocommerce:*:*:*:*:*:wordpress:*:*

History

No history.

Information

Published : 2024-03-13 16:15

Updated : 2025-02-28 15:16


NVD link : CVE-2024-0683

Mitre link : CVE-2024-0683

CVE.ORG link : CVE-2024-0683


JSON object : View

Products Affected

autopolis

  • bulgarisation_for_woocommerce
CWE
CWE-862

Missing Authorization