Analytics for Woo – Putler Accurate Analytics and Reports for your WooCommerce Store [woocommerce-putler-connector] < 2.13.0
unknown
[en] Missing Authorization vulnerability in Putler / Storeapps Putler Connector for WooCommerce.This issue affects Putler Connector for WooCommerce: from n/a through 2.12.0.
- Affected:
- up to 2.13.0
- Fixed in:
- 2.13.0
- Disclosed:
- Jan 2, 2025
CVE-2023-40327 on NVD →
Putler Connector for WooCommerce <= 2.12.0 - Missing Authorization via 'putler_connector_sync_complete'
medium
The Putler Connector for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the putler_connector_sync_complete() function in versions up to, and including, 2.12.0. This makes it possible for unauthenticated attackers to delete the putler_connector_re...
- CVSS:
- 5.3
- Affected:
- up to 2.12.0
- Fixed in:
- 2.13.0
- Disclosed:
- Aug 15, 2023
CVE-2023-40327 on NVD →
Putler Connector for WooCommerce <= 2.12.0 - Missing Authorization via 'send_resync_request'
medium
The Putler Connector for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the send_resync_request() function called via an AJAX action in versions up to, and including, 2.12.0. This makes it possible for authenticated attackers, with subscriber-lev...
- CVSS:
- 4.3
- Affected:
- up to 2.12.0
- Fixed in:
- 2.13.0
- Disclosed:
- Aug 15, 2023
CVE-2023-40326 on NVD →
Analytics for Woo – Putler Accurate Analytics and Reports for your WooCommerce Store [woocommerce-putler-connector] < 2.13.0
unknown
** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.
- Affected:
- up to 2.13.0
- Fixed in:
- 2.13.0
CVE-2023-40326 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database