CVE-2024-10614 affects the Customer Reviews for WooCommerce WordPress plugin, versions up to and including 5.61.0, due to a missing capability check in the cancel_import() function. This allows authenticated users with Subscriber-level access or higher to cancel or check the status of imports without proper authorization. Rated Medium severity (CVSS 4.3), the vulnerability has low attack complexity and could lead to unauthorized modification of import processes, though it does not directly impact confidentiality or availability. There is currently no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 5.61.1CPE matchmatch criteria | cpe:2.3:a:cusrev:customer_reviews_for_woocommerce:*:*:*:*:*:wordpress:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.