CVE-2024-50945
High severity, CVSS 7.5. EPSS: 0.6% chance of exploitation in the next 30 days.
An improper access control vulnerability exists in SimplCommerce at commit 230310c8d7a0408569b292c5a805c459d47a1d8f, allowing users to submit reviews without verifying if they have purchased the product.
Published 2024-12-27. Last modified 2026-06-17.