CVE-2024-12826

CVSS 3.1 Score 4.3 of 10 (medium)

Details

Published Jan 25, 2025
CWE ID 862

Summary

CVE-2024-12826 is a vulnerability affecting the GoHero Store Customizer plugin for WooCommerce used on WordPress sites. The issue lies in the wooh_action_settings_save_frontend() function, which lacks essential capability checks. Consequently, unauthenticated attackers can exploit this flaw to modify limited plugin settings, posing a potential security risk for affected WordPress installations. The vulnerability is present in all plugin versions up to and including 3.5. Users are encouraged to update the plugin as soon as possible to mitigate this threat.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share