CVE-2024-1310: Automattic Woocommerce
Medium severity, CVSS 4.9. EPSS: 0.7% chance of exploitation in the next 30 days.
The WooCommerce WordPress plugin before 8.6 does not prevent users with at least the contributor role from leaking products they shouldn't have access to. (e.g. private, draft and trashed products)
Affected products
- Automattic Woocommerce: before 8.6.0 (fixed in 8.6.0)
Published 2024-04-15. Last modified 2026-07-20.