CVE Database /
CVE-2024-9189
CVE · Medium
CVE-2024-9189 — EU/UK VAT Validation Manager for WooCommerce [eu-vat-for-woocommerce] < 2.12.14
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2024-9189
|
EU/UK VAT Validation Manager for WooCommerce [eu-vat-for-woocommerce] < 2.12.14 |
Missing Authorization |
Medium
5.3
|
< 2.12.14
|
2.12.14 |
2024-09-27 |
—
|
CVE-2024-9189
The WooCommerce plugin for WordPress, specifically the EU/UK VAT Manager, has a security flaw in its data modification process. In versions up to and including 2.12.12, the plugin does not properly verify user permissions, allowing unauthorized attackers to modify VAT status for any order without requiring authentication. This vulnerability enables attackers to make unauthorized changes to order data.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings