The Sharkdropship for AliExpress Dropshipping and Affiliate plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the wads_removeProductFromShop() function in all versions up to, and including, 2.2.4. This makes it possible for unauthenticated attackers to delete arbitrary posts.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published: 2024-04-02T09:32:09.089Z

Updated: 2024-08-09T19:00:16.574Z

Reserved: 2024-02-22T01:36:34.407Z

Link: CVE-2024-1732

cve-icon Vulnrichment

Updated: 2024-08-01T18:48:21.821Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-04-02T10:15:07.900

Modified: 2024-11-21T08:51:11.253

Link: CVE-2024-1732

cve-icon Redhat

No data.