CVE-2024-13511 MEDIUM

CVE-2024-13511: Variation Swatches for WooCommerce 1.0.8 - 1.3.2 - Cross-Site Request Forgery to Plugin Settings Reset

Vendor Themehunk
Product Variation Swatches for WooCommerce
Weakness CWE-352 · CSRF
Published January 23, 2025
Last update January 23, 2025

CVSS base score

4.3/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction Required
Confidentiality None
Integrity Low

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N

What the vulnerability does

01Description

The Variation Swatches for WooCommerce plugin, in all versions starting at 1.0.8 up until 1.3.2, contains a vulnerability due to improper nonce verification in its settings reset functionality. The issue exists in the settings_init() function, which processes a reset action based on specific query parameters in the URL. The related delete_settings() function performs a faulty nonce validation check, making the reset operation insecure and susceptible to unauthorized access.

Key dates

02Disclosure timeline

January 23, 2025 CVE published
January 23, 2025 Record updated

Related vulnerabilities

04Related CVE