CVE-2024-1516 MEDIUM

CVE-2024-1516: WP eCommerce <= 3.15.1 - Missing Authorization to Unauthenticated Arbitrary Post Creation

Vendor Justinsainton
Product WP eCommerce
Weakness CWE-862 · Missing authorization
Published February 28, 2024
Last update April 8, 2026

CVSS base score

5.3/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Confidentiality None
Integrity Low

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

What the vulnerability does

01Description

The WP eCommerce plugin for WordPress is vulnerable to unauthorized arbitrary post creation due to a missing capability check on the check_for_saas_push() function in all versions up to, and including, 3.15.1. This makes it possible for unauthenticated attackers to create arbitrary posts with arbitrary content.

Key dates

02Disclosure timeline

February 28, 2024 CVE published
April 8, 2026 Record updated