Point of Sale System for WooCommerce [woo-point-of-sale] < 6.2.0
unknown
[en] The WooCommerce Point of Sale plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 6.1.0. This is due to insufficient validation on the 'logged_in_user_id' value when option values are empty and the ability for attackers to change the email of arbitrary user accounts. Th...
- Affected:
- up to 6.2.0
- Fixed in:
- 6.2.0
- Disclosed:
- Dec 25, 2024
CVE-2024-11281 on NVD →
WooCommerce Point of Sale <= 6.1.0 - Insecure Direct Object Reference to Privilege Escalation via Arbitrary User Email Change
critical
The WooCommerce Point of Sale plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 6.1.0. This is due to insufficient validation on the 'logged_in_user_id' value when option values are empty and the ability for attackers to change the email of arbitrary user accounts. This ma...
- CVSS:
- 9.8
- Affected:
- up to 6.1.0
- Fixed in:
- 6.2.0
- Disclosed:
- Dec 24, 2024
CVE-2024-11281 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database