Description
The WooCommerce Customers Manager WordPress plugin before 30.2 does not have authorisation and CSRF in various AJAX actions, allowing any authenticated users, such as subscriber, to call them and update/delete/create customer metadata, also leading to Stored Cross-Site Scripting due to the lack of escaping of said metadata values.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
History
Thu, 29 May 2025 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Vanquish
Vanquish woocommerce Customers Manager |
|
| Weaknesses | CWE-352 | |
| CPEs | cpe:2.3:a:vanquish:woocommerce_customers_manager:*:*:*:*:*:wordpress:*:* | |
| Vendors & Products |
Vanquish
Vanquish woocommerce Customers Manager |
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2024-08-01T14:24:07.026Z
Reserved: 2024-02-22T14:14:40.146Z
Link: CVE-2024-1747
Updated: 2024-08-01T14:24:03.894Z
Status : Analyzed
Published: 2024-08-01T06:15:01.980
Modified: 2025-05-29T17:23:24.683
Link: CVE-2024-1747
No data.
OpenCVE Enrichment
No data.
Weaknesses