CVE-2024-24719
CVE-2024-24719 is a Missing Authorization vulnerability found in the Uriahs Victor Location Picker at Checkout for WooCommerce plugin, versions up to 1.8.9. This vulnerability allows unauthorized actions due to insufficient access controls within the plugin. While the CVSS score is 0, indicating a base score of no immediate impact, the SOCRadar Vulnerability Risk Score (SVRS) of 30 suggests a low level of exploitability or real-world risk at this time. The risk stems from the potential for attackers to bypass intended security measures and manipulate location data during the checkout process. The impact could range from minor disruptions to potential fraud, depending on how the vulnerability is exploited within a specific WooCommerce implementation. Despite the low SVRS, it is crucial to patch vulnerabilities promptly to prevent exploitation.
Indicators of Compromise
Exploits
News
Social Media
Affected Software
References
CWE Details
CVE Radar
Real-time CVE Intelligence & Vulnerability Management Platform
CVE Radar provides comprehensive vulnerability intelligence by monitoring CVE databases, security advisories, and threat feeds. Get instant updates on new vulnerabilities, exploit details, and mitigation strategies specific to your assets.