5.3

CVE-2024-9189

EU/UK VAT Manager for WooCommerce <= 2.12.12 - Missing Authorization

The EU/UK VAT Manager for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the alg_wc_eu_vat_exempt_vat_from_admin() function in all versions up to, and including, 2.12.12. This makes it possible for unauthenticated attackers to update the VAT status for any order.
Mögliche Gegenmaßnahme
EU/UK VAT Validation Manager for WooCommerce: Update to version 2.12.14, or a newer patched version
Weitere Schwachstelleninformationen
SystemWordPress Plugin
Produkt EU/UK VAT Validation Manager for WooCommerce
Version * - 2.12.12
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
WpfactoryEu/uk Vat Manager For Woocommerce SwPlatformwordpress Version < 2.12.14
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.17% 0.387
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
security@wordfence.com 5.3 3.9 1.4
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
CWE-862 Missing Authorization

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.