WordPress Plugin Vulnerabilities
WooCommerce Conversion Tracking < 2.0.12 - Subscriber+ happy-elementor-addons Installation & Activation
Description
The plugin does not have authorisation checks in some AJAX actions, which could allow any authenticated users, such as subscriber to install and activate the happy-elementor-addons addon plugin
Affects Plugins
References
Classification
Type
NO AUTHORISATION
OWASP top 10
CWE
CVSS
Miscellaneous
Original Researcher
Abdi Pranata
Verified
No
WPVDB ID
Timeline
Publicly Published
2024-01-03 (about 2 years ago)
Added
2024-01-12 (about 2 years ago)
Last Updated
2024-01-18 (about 2 years ago)