CVE-2024-13652
CVSS 3.1 Score 4.3 of 10 (medium)
Details
Published Jan 30, 2025
Updated: Jan 31, 2025
CWE ID 862
Summary
CVE-2024-13652: The ECPay Ecommerce plugin for WooCommerce and WordPress, affecting versions up to 1.1.2411060, contains a vulnerability. An unchecked capability is present in the 'clear_ecpay_debug_log' AJAX action, allowing authenticated attackers with Subscriber-level access or higher to clear the plugin's log files, potentially leading to unauthorized data loss.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share