CVE-2024-0617 describes an unauthorized data modification vulnerability in the Category Discount Woocommerce plugin for WordPress, affecting all versions up to 4.12. This flaw allows unauthenticated attackers to alter product category discounts due to a missing capability check in the wpcd_save_discount() function. Rated as Medium severity (CVSS 5.3), the vulnerability has a low attack complexity and requires no user interaction, making it easily exploitable over the network. The primary impact is a potential loss of revenue for affected e-commerce sites. Currently, there is no evidence of active exploitation, nor is public exploit code available in Metasploit, Nuclei, or ExploitDB. The CVE has also received minimal community discussion and media coverage, indicating a low level of public awareness.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 4.13CPE matchmatch criteria | cpe:2.3:a:quanticedgesolutions:category_discount_woocommerce:*:*:*:*:*:wordpress:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.