CVE · Medium

CVE-2024-1310 — WooCommerce [woocommerce] < 8.6

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2024-1310 WooCommerce [woocommerce] < 8.6 Improper Access Control Medium 4.9 < 8.6 8.6 2024-03-25

CVE-2024-1310

The WooCommerce plugin contains an authorization flaw in its product shortcode affecting versions 8.5.2 and earlier that allows authenticated users with contributor permissions or higher to access and view products marked as private or in draft status. This vulnerability permits unauthorized disclosure of product information that should remain restricted to administrators and other approved users. The issue stems from inadequate access controls within the shortcode functionality.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.