CVE-2024-1310
The WooCommerce plugin contains an authorization flaw in its product shortcode affecting versions 8.5.2 and earlier that allows authenticated users with contributor permissions or higher to access and view products marked as private or in draft status. This vulnerability permits unauthorized disclosure of product information that should remain restricted to administrators and other approved users. The issue stems from inadequate access controls within the shortcode functionality.
Based on public CVE data (MITRE/NVD).