CVE-2024-9189

CVSS 3.1 Score 5.3 of 10 (medium)

Details

Published Sep 28, 2024
Updated: Oct 3, 2024
CWE ID 862

Summary

CVE-2024-9189 is a vulnerability affecting the EU/UK VAT Manager plugin for WordPress, specifically the alg_wc_eu_vat_exempt_vat_from_admin() function. In all versions up to 2.12.12, this function lacks sufficient capability checks, enabling unauthenticated attackers to manipulate VAT statuses for any order. This vulnerability could lead to significant financial losses for e-commerce sites using the plugin.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share