CVE-2024-12826
CVSS 3.1 Score 4.3 of 10 (medium)
Details
Published Jan 25, 2025
CWE ID 862
Summary
CVE-2024-12826 is a vulnerability affecting the GoHero Store Customizer plugin for WooCommerce used on WordPress sites. The issue lies in the wooh_action_settings_save_frontend() function, which lacks essential capability checks. Consequently, unauthenticated attackers can exploit this flaw to modify limited plugin settings, posing a potential security risk for affected WordPress installations. The vulnerability is present in all plugin versions up to and including 3.5. Users are encouraged to update the plugin as soon as possible to mitigate this threat.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.