cleantalk
Vulnerabilities and Security Researches

Order Tip for WooCommerce, CVE-2024-1119

CVE, Research URL

CVE-2024-1119

Published on
Mar 20, 2024
Research Description
The Order Tip for WooCommerce plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the export_tips_to_csv() function in all versions up to, and including, 1.3.1. This makes it possible for unauthenticated attackers to export the plugin's order fees.
Affected versions
Min -, max 1.4.0.
Status
vulnerable