CVE-2024-3243CVSS 4.3Web
CVE-2024-3243: customer reviews for woocommerce vulnerability
The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to unauthorized email sending due to a missing capability check on the send_test_email() function in all versions up to, and including, 5.46.0. This makes it possible for authenticated attackers, with subscriber-level access and above, to send arbitrary test emails.
- CVSS
- 4.3 MEDIUM
- EPSS
- 35.26%
- Known exploited
- not in KEV
- Product
- customer reviews for woocommerce
What is known
The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to unauthorized email sending due to a missing capability check on the send_test_email() function in all versions up to, and including, 5.46.0. This makes it possible for authenticated attackers, with subscriber-level access and above, to send arbitrary test emails.