Description

The Variation Swatches for WooCommerce plugin, in all versions starting at 1.0.8 up until 1.3.2, contains a vulnerability due to improper nonce verification in its settings reset functionality. The issue exists in the settings_init() function, which processes a reset action based on specific query parameters in the URL. The related delete_settings() function performs a faulty nonce validation check, making the reset operation insecure and susceptible to unauthorized access.

INFO

Published Date :

2025-01-23T09:21:08.768Z

Last Modified :

2025-01-23T14:45:05.787Z

Source :

Wordfence
AFFECTED PRODUCTS

The following products are affected by CVE-2024-13511 vulnerability.

Vendors Products
Variation Swatches For Woocommerce Project
  • Variation Swatches For Woocommerce

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact