Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-47826 | The YITH Essential Kit for WooCommerce #1 plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'activate_module', 'deactivate_module', and 'install_module' functions in all versions up to, and including, 2.34.0. This makes it possible for authenticated attackers, with Subscriber-level access and above, to install, activate, and deactivate plugins from a pre-defined list of available YITH plugins. |
Fri, 10 Apr 2026 04:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 10 Sep 2024 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Yithemes
Yithemes yith Essential Kit For Woocommerce |
|
| CPEs | cpe:2.3:a:yithemes:yith_essential_kit_for_woocommerce:*:*:*:*:*:wordpress:*:* | |
| Vendors & Products |
Yithemes
Yithemes yith Essential Kit For Woocommerce |
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2026-04-08T17:22:06.864Z
Reserved: 2024-07-16T18:59:38.502Z
Link: CVE-2024-6799
Updated: 2024-08-01T21:45:37.990Z
Status : Modified
Published: 2024-07-19T08:15:03.153
Modified: 2024-11-21T09:50:20.830
Link: CVE-2024-6799
No data.
OpenCVE Enrichment
No data.
EUVD