CVE-2024-0797

T

he Active Products Tables for WooCommerce. Professional products tables for WooCommerce store plugin for WordPress is vulnerable to unauthorized access of functionality due to a missing capability check on several functions in all versions up to, and including, 1.0.6.1. This makes it possible for subscribers and higher to execute functions intended for admin use.

Configurations

Configuration 1 (hide)

cpe:2.3:a:pluginus:woot:*:*:*:*:*:wordpress:*:*

History

21 Nov 2024, 08:47

Type Values Removed Values Added
References () https://plugins.trac.wordpress.org/changeset/3029488/profit-products-tables-for-woocommerce/trunk?contextall=1&old=3005088&old_path=%2Fprofit-products-tables-for-woocommerce%2Ftrunk - Patch () https://plugins.trac.wordpress.org/changeset/3029488/profit-products-tables-for-woocommerce/trunk?contextall=1&old=3005088&old_path=%2Fprofit-products-tables-for-woocommerce%2Ftrunk - Patch
References () https://www.wordfence.com/threat-intel/vulnerabilities/id/0a94841f-b1dd-44f4-b7a1-65a9fdf7b18d?source=cve - Third Party Advisory () https://www.wordfence.com/threat-intel/vulnerabilities/id/0a94841f-b1dd-44f4-b7a1-65a9fdf7b18d?source=cve - Third Party Advisory

Information

Published : 2024-02-05 22:16

Updated : 2025-05-15 20:15


NVD link : CVE-2024-0797

Mitre link : CVE-2024-0797

CVE.ORG link : CVE-2024-0797


JSON object : View

Products Affected
CWE
CWE-862

Missing Authorization