CVE-2024-13343

CVSS 3.1 Score 8.8 of 10 (high)

Details

Published Feb 1, 2025
CWE ID 269

Summary

CVE-2024-13343 is a privilege escalation vulnerability affecting the WooCommerce Customers Manager plugin for WordPress. Authenticated attackers with Subscriber-level access or higher can exploit this vulnerability, which stems from a missing capability check in the ajax_assign_new_roles() function. By successfully exploiting this flaw, attackers can elevate their privileges to that of an administrator. This vulnerability exists in all versions up to and including 31.3, potentially impacting a significant number of WordPress websites utilizing this plugin.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share