Security Advisory
CVE-2024-0201
5.4
MEDIUM
Vulnerability Description
The Product Expiry for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'save_settings' function in versions up to, and including, 2.5. This makes it possible for authenticated attackers, with subscriber-level permissions or above to update plugin settings. CVE-2023-52179 appears to be a duplicate of this issue.
Published Date
January 3, 2024
Official Source
NIST NVD Advisory