CVE-2024-1310

WooCommerce < 8.6 - Contributor+ Private/Draft Products Access

The WooCommerce WordPress plugin before 8.6 does not prevent users with at least the contributor role from leaking products they shouldn't have access to. (e.g. private, draft and trashed products)


We have discovered 536,829 live websites that are affected by CVE-2024-1310.

Test my site




Affected Software

Product  WooCommerce
Category Ecommerce
Vulnerable Domains536,829 live websites (35.85% of WooCommerce install base)
Vulnerable Versions
  • from 0 before 8.6
Vulnerable Versions Count425 versions ( 88.17% of all versions)


Common Weakness Enumeration

CWE-284 Improper Access Control



Details

  • Published - Apr 15, 2024
  • Updated - Oct 31, 2024

Credits

  • Scott Kingsley Clark (finder)
  • WPScan (coordinator)

CVE-2024-1310 usage by Country

United States156,461 websites



Germany53,218 websites
France35,632 websites
Russia22,478 websites
GB21,887 websites
Vietnam16,448 websites
Spain15,251 websites
Netherlands14,517 websites
Italy14,282 websites
Poland13,420 websites

CVE-2024-1310 usage by TLD

.com235,005 websites
.ru18,232 websites
.de15,509 websites
.co.uk15,308 websites
.org13,352 websites
.nl13,251 websites
.it12,180 websites
.fr10,896 websites
.pl10,785 websites
.com.au10,534 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2024-1310

Top websites that are affected by CVE-2024-1310. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
***.com United States*,***
***********.com United States*,***
*****************.com United States*,***
*************.com United States*,***
**********.com United States*,***
**********.com Czech Republic*,***
*********.com United States*,***
************.ie United States*,***
*********.com United States*,***
**********.com United States*,***
See full domain list

FAQ

CVE-2024-1310 is Improper Access Control in WooCommerce
A total of 536,829 websites have been identified as vulnerable to CVE-2024-1310, discovered through global website indexing conducted by WebTechSurvey.
WooCommerce is susceptible to CVE-2024-1310 vulnerability.
WooCommerce versions before 8.6 are vulnerable to CVE-2024-1310.
Version 8.6 of WooCommerce addresses the CVE-2024-1310 security vulnerability.