Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-51642 | The Variation Swatches for WooCommerce plugin, in all versions starting at 1.0.8 up until 1.3.2, contains a vulnerability due to improper nonce verification in its settings reset functionality. The issue exists in the settings_init() function, which processes a reset action based on specific query parameters in the URL. The related delete_settings() function performs a faulty nonce validation check, making the reset operation insecure and susceptible to unauthorized access. |
Wed, 05 Feb 2025 18:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Variation Swatches For Woocommerce Project
Variation Swatches For Woocommerce Project variation Swatches For Woocommerce |
|
| CPEs | cpe:2.3:a:variation_swatches_for_woocommerce_project:variation_swatches_for_woocommerce:*:*:*:*:*:wordpress:*:* | |
| Vendors & Products |
Variation Swatches For Woocommerce Project
Variation Swatches For Woocommerce Project variation Swatches For Woocommerce |
Thu, 23 Jan 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 23 Jan 2025 09:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Variation Swatches for WooCommerce plugin, in all versions starting at 1.0.8 up until 1.3.2, contains a vulnerability due to improper nonce verification in its settings reset functionality. The issue exists in the settings_init() function, which processes a reset action based on specific query parameters in the URL. The related delete_settings() function performs a faulty nonce validation check, making the reset operation insecure and susceptible to unauthorized access. | |
| Title | Variation Swatches for WooCommerce 1.0.8 - 1.3.2 - Cross-Site Request Forgery to Plugin Settings Reset | |
| Weaknesses | CWE-352 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2025-01-23T14:45:05.787Z
Reserved: 2025-01-17T15:27:00.611Z
Link: CVE-2024-13511
Updated: 2025-01-23T14:45:00.979Z
Status : Undergoing Analysis
Published: 2025-01-23T10:15:07.253
Modified: 2025-02-05T18:22:40.217
Link: CVE-2024-13511
No data.
OpenCVE Enrichment
No data.
EUVD