Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2024-1310


The WooCommerce WordPress plugin before 8.6 does not prevent users with at least the contributor role from leaking products they shouldn't have access to. (e.g. private, draft and trashed products)


Published

2024-04-15T05:15:14.857

Last Modified

2025-05-27T16:13:32.967

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 4.9 (MEDIUM)

Weaknesses
  • Type: Primary
    NVD-CWE-noinfo

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application automattic woocommerce < 8.6 Yes

References