CVE-2024-1310

WooCommerce < 8.6 - Contributor+ Private/Draft Products Access

The WooCommerce WordPress plugin before 8.6 does not prevent users with at least the contributor role from leaking products they shouldn't have access to. (e.g. private, draft and trashed products)


We have discovered 312,858 live websites that are affected by CVE-2024-1310.

Run a Free Instant Scan




Affected Software

Product  WooCommerce
Category Ecommerce
Vulnerable Domains312,858 live websites (24% of WooCommerce install base)
Vulnerable Versions
  • from 0 through 8.6
Vulnerable Versions Count371 versions ( 75% of all versions)


Common Weakness Enumeration

CWE-284 Improper Access Control



Details

  • Published - Apr 15, 2024
  • Updated - Oct 31, 2024

Credits

  • Scott Kingsley Clark (finder)
  • WPScan (coordinator)

Website Distribution by Country

Number of websites using CVE-2024-1310
United States68,177 websites



Germany24,259 websites
France17,775 websites
Italy17,449 websites
Russia16,213 websites
GB14,154 websites
Vietnam10,478 websites
Spain10,367 websites
Netherlands8,846 websites
Poland8,041 websites

Website Distribution by TLD

Number of websites using CVE-2024-1310
.com132,243 websites
.ru12,707 websites
.it11,892 websites
.de9,530 websites
.co.uk8,570 websites
.org7,467 websites
.nl7,328 websites
.fr6,550 websites
.pl6,019 websites
.net5,882 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2024-1310

Top websites that are affected by CVE-2024-1310. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
***.com United States*,***
***********.com United States*,***
*****************.com United States*,***
*************.com United States*,***
**********.com Czech Republic*,***
*********.com United States*,***
************.ie United States*,***
**********.com United States*,***
*********.com Netherlands**,***
***********.net United States**,***
See full domain list

FAQ

CVE-2024-1310 is Improper Access Control in WooCommerce
A total of 312,858 websites have been identified as vulnerable to CVE-2024-1310, based on global website indexing conducted by WebTechSurvey.
The WooCommerce is affected by the CVE-2024-1310 vulnerability.
WooCommerce versions up to 8.6 are vulnerable to CVE-2024-1310.
CVE-2024-1310 is resolved in version 8.6 of WooCommerce.