← Back to CVE List

CVE-2024-9189

Published: 2024-09-28T02:15Z
Last Modified: 2024-10-03T17:26Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
The EU/UK VAT Manager for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the alg_wc_eu_vat_exempt_vat_from_admin() function in all versions up to, and including, 2.12.12. This makes it possible for unauthenticated attackers to update the VAT status for any order. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt