CVE-2024-52395

CVSS 3.1 Score 5.3 of 10 (medium)

Details

Published Nov 19, 2024
CWE ID 862

Summary

CVE-2024-52395 is a newly disclosed vulnerability affecting the QunatumCloud Floating Buttons plugin for WooCommerce. This issue involves a missing authorization control, allowing unauthorized access to certain functionalities. The vulnerability can be exploited when access control security levels are incorrectly configured. The Floating Buttons plugin, which is used to create and manage floating buttons on WooCommerce sites, is impacted from versions n/a through 2.8.8. Successful exploitation could lead to significant security risks, making it essential for affected users to apply the necessary patches as soon as possible.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share