← Back

CVE-2024-13511

nvd nist
Published: Jan 23, 2025Modified: Feb 5, 2025

JSON object

Loading...
4.3
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
Exploitability: 2.8 / Impact: 1.4
Source: security@wordfence.com (Secondary)

Description

The Variation Swatches for WooCommerce plugin, in all versions starting at 1.0.8 up until 1.3.2, contains a vulnerability due to improper nonce verification in its settings reset functionality. The issue exists in the settings_init() function, which processes a reset action based on specific query parameters in the URL. The related delete_settings() function performs a faulty nonce validation check, making the reset operation insecure and susceptible to unauthorized access.

Affected (1)

Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
From 1.0.8 to 1.3.3

Timeline

No history available yet.