CVE-2024-1310

CVE-2024-1310: WooCommerce < 8.6 - Contributor+ Private/Draft Products Access

Vendor Unknown
Product WooCommerce
Published April 15, 2024
Last update October 31, 2024

CVSS base score

What the vulnerability does

01Description

The WooCommerce WordPress plugin before 8.6 does not prevent users with at least the contributor role from leaking products they shouldn't have access to. (e.g. private, draft and trashed products)

Key dates

02Disclosure timeline

April 15, 2024 CVE published
October 31, 2024 Record updated