WordPress Plugin Vulnerabilities

WooCommerce Conversion Tracking < 2.0.12 - Subscriber+ happy-elementor-addons Installation & Activation

Description

The plugin does not have authorisation checks in some AJAX actions, which could allow any authenticated users, such as subscriber to install and activate the happy-elementor-addons addon plugin

Affects Plugins

References

Classification

Type
NO AUTHORISATION
CWE

Miscellaneous

Original Researcher
Abdi Pranata
Verified
No

Timeline

Publicly Published
2024-01-03 (about 2 years ago)
Added
2024-01-12 (about 2 years ago)
Last Updated
2024-01-18 (about 2 years ago)

Other