CVE-2024-1686 Information
Feb 29, 2024
cve
Description
The Thank You Page Customizer for WooCommerce – Increase Your Sales plugin for WordPress is vulnerable to missing authorization e in all versions up to and including 1.1.2 via the apply_layout function due to a missing capability check. This makes it possible for authenticated attackers with subscriber-level access and above to retrieve arbitrary order data which may contain PII.
Reference
https://www.wordfence.com/threat-intel/vulnerabilities/id/2e7ebc0c-6936-4632-a602-7131c7d8bd6a?source=cve https://plugins.trac.wordpress.org/changeset/3041096/woo-thank-you-page-customizer/trunk/frontend/frontend.php
Share on: