CVE-2024-10567: TI WooCommerce Wishlist <= 2.9.1 - Missing Authorization to Unauthenticated Plugin Setup Wizard Access
The TI WooCommerce Wishlist plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'wizard' function in all versions up to, and including, 2.9.1. This makes it possible for unauthenticated attackers to create new pages, modify plugin settings, and perform limited options updates.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-10567?
CVE-2024-10567 is considered a high severity vulnerability due to the potential for unauthorized data modification.
How do I fix CVE-2024-10567?
To fix CVE-2024-10567, update the TI WooCommerce Wishlist plugin to version 2.9.2 or later.
Who is affected by CVE-2024-10567?
CVE-2024-10567 affects all versions of the TI WooCommerce Wishlist plugin up to and including 2.9.1.
What kind of attack can be conducted due to CVE-2024-10567?
Due to CVE-2024-10567, unauthorized attackers can create new pages and modify existing data without authentication.
Is a patch available for CVE-2024-10567?
Yes, a patch has been released in version 2.9.2 of the TI WooCommerce Wishlist plugin to address CVE-2024-10567.