Vulnerability Description
The EU/UK VAT Manager for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the alg_wc_eu_vat_exempt_vat_from_admin() function in all versions up to, and including, 2.12.12. This makes it possible for unauthenticated attackers to update the VAT status for any order.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Wpfactory | Eu\/Uk Vat Manager For Woocommerce | < 2.12.14 |
Related Weaknesses (CWE)
References
- https://plugins.trac.wordpress.org/browser/eu-vat-for-woocommerce/tags/2.12.12/iProduct
- https://plugins.trac.wordpress.org/changeset/3158296/Patch
- https://www.wordfence.com/threat-intel/vulnerabilities/id/c6db680e-1fd4-420c-98fThird Party Advisory
FAQ
What is CVE-2024-9189?
CVE-2024-9189 is a vulnerability with a CVSS score of 5.3 (MEDIUM). The EU/UK VAT Manager for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the alg_wc_eu_vat_exempt_vat_from_admin() function in...
How severe is CVE-2024-9189?
CVE-2024-9189 has been rated MEDIUM with a CVSS base score of 5.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-9189?
Check the references section above for vendor advisories and patch information. Affected products include: Wpfactory Eu\/Uk Vat Manager For Woocommerce.