CVE-2024-12004
Published
CVSS v3
6.1
MEDIUM
CVSS v2
N/A
Affected
1
PROJECT
Description
The WPC Order Notes for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.5.2. This is due to missing or incorrect nonce validation on the ajax_update_order_note() function. This makes it possible for unauthenticated attackers to inject malicious web scripts via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
<p><strong>WPC Order Notes for WooCommerce</strong> is an easy tool for store owners to manage all order notes. It offers a quick preview of added notes in each order from the popup. It lists all the notes with paging and provides the search function for finding the needed detail quickly.</p>
<p><strong>WPC Order Notes for WooCommerce</strong> makes life easier for store managers by reducing the time needed for organizing notes, checking orders to find the latest activity, or navigating back and forth to check the progress during the package delivery.</p>
<h4>Features</h4>
<ul>
<li>List all notes with paging</li>
<li>Add quick notes to quickly select</li>
<li>Search for matching notes in the Notes section</li>
<li>Preview the latest notes from the Orders section</li>
<li>Quick view all notes of an order from the popup</li>
<li>Add/ edit/ delete a note on the quick view popup</li>
</ul>
<h4>Not what you needed?</h4>
<p>Please try other plugins from us:</p>
<ul>
<li><a href="https://wordpress.org/plugins/woo-product-bundle/" title="WPC Product Bundles" rel="ugc">WPC Product Bundles</a></li>
<li><a href="https://wordpress.org/plugins/wpc-composite-products/" title="WPC Composite Products" rel="ugc">WPC Composite Products</a></li>
<li><a href="https://wordpress.org/plugins/wpc-grouped-product/" title="WPC Grouped Product" rel="ugc">WPC Grouped Product</a></li>
<li><a href="https://wordpress.org/plugins/woo-bought-together/" title="WPC Frequently Bought Together" rel="ugc">WPC Frequently Bought Together</a></li>
<li><a href="https://wordpress.org/plugins/wpc-force-sells/" title="WPC Force Sells" rel="ugc">WPC Force Sells</a></li>
</ul>