CVE-2024-11281
CVSS 3.1 Score 9.8 of 10 (high)
Details
Published Dec 25, 2024
CWE ID 862
Summary
CVE-2024-11281 is a privilege escalation vulnerability affecting the WooCommerce Point of Sale plugin for WordPress. In versions up to 6.1.0, insufficient validation on 'logged_in_user_id' values for empty option values enables attackers to manipulate the email addresses of arbitrary user accounts. This vulnerability allows unauthenticated attackers to change the email of administrator accounts and reset their passwords, granting unauthorized access.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.