CVE-2024-13775 - WooCommerce Support Ticket System for WordPress Unauthorized Access and Data Loss Vulnerability

4 hours ago 1
ARTICLE AD BOX
CVE ID : CVE-2024-13775
Published : Feb. 1, 2025, 1:15 p.m. | 1 hour, 39 minutes ago
Description : The WooCommerce Support Ticket System plugin for WordPress is vulnerable to unauthorized access and loss of data due to missing capability checks on the 'ajax_delete_message', 'ajax_get_customers_partial_list', and 'ajax_get_admins_list' functions in all versions up to, and including, 17.8. This makes it possible for authenticated attackers, with Subscriber-level access and above, to delete arbitrary posts, and read names, emails, and capabilities of all users.
Severity: 5.4 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Read Entire Article