PoC Index

CVE-2024-1756

MEDIUM 6.5EPSS 0.3%

The WooCommerce Customers Manager WordPress plugin before 29.8 does not have authorisation and CSRF in an AJAX action, allowing any authenticated users, such as subscriber, to call it and retrieve the list of customer email addresses along with their id, first name and last name

CVSS v3.1
6.5 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
EPSS
0.32% chance of exploitation in the next 30 days, 24th percentile
Published
2024-04-24
Updated
2025-03-20

Proof-of-concept exploits (1)

References

Related