7.5
CVE-2024-43131
- EPSS 0.42%
- Veröffentlicht 13.08.2024 11:15:18
- Zuletzt bearbeitet 28.01.2026 18:45:44
- Quelle audit@patchstack.com
- CVE-Watchlists
- Unerledigt
Docket (WooCommerce Collections / Wishlist / Watchlist) < 1.7.0 - Missing Authorization to Unauthenticated Arbitrary Post/Page Deletion
Incorrect Authorization vulnerability in WPWeb Docket (WooCommerce Collections / Wishlist / Watchlist) allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Docket (WooCommerce Collections / Wishlist / Watchlist): from n/a before 1.7.0.
Mögliche Gegenmaßnahme
Docket (WooCommerce Collections / Wishlist / Watchlist): Update to version 1.7.0, or a newer patched version
Weitere Schwachstelleninformationen
SystemWordPress Plugin
≫
Produkt
Docket (WooCommerce Collections / Wishlist / Watchlist)
Version
[*, 1.7.0)
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Wpwebelite ≫ Docket SwPlatformwordpress Version < 1.7.0
Wpwebelite ≫ Docket Version1.7.0 SwPlatformwordpress
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.42% | 0.614 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 7.5 | 3.9 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
|
| audit@patchstack.com | 7.5 | 3.9 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
|
CWE-863 Incorrect Authorization
The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.