Feed/CVE-2024-1310
CVE-2024-1310MEDIUMCVSS 4.9

CVE-2024-1310

Published Apr 15, 2024·Updated Jul 20, 2026

NVD Description

The WooCommerce WordPress plugin before 8.6 does not prevent users with at least the contributor role from leaking products they shouldn't have access to. (e.g. private, draft and trashed products)

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N

References

View on NVD Search GitHub Search Google

Get alerted for CVEs like this

Register your stack and get notified within minutes when a matching CVE drops.

Start monitoring free