CVE-2024-13652

CVSS 3.1 Score 4.3 of 10 (medium)

Details

Published Jan 30, 2025
Updated: Jan 31, 2025
CWE ID 862

Summary

CVE-2024-13652: The ECPay Ecommerce plugin for WooCommerce and WordPress, affecting versions up to 1.1.2411060, contains a vulnerability. An unchecked capability is present in the 'clear_ecpay_debug_log' AJAX action, allowing authenticated attackers with Subscriber-level access or higher to clear the plugin's log files, potentially leading to unauthorized data loss.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share