CVE-2024-5324
XootiX Framework <= Various Plugin Versions - Missing Authorization to Arbitrary Options Update
CVSS Score
8.8
EPSS Score
0.0%
EPSS Percentile
0th
Multiple plugins for WordPress utilizing the XootiX Framework are vulnerable to unauthorized modification of data due to a missing capability check on the 'import_settings' function in various versions. This makes it possible for authenticated attackers, with Subscriber-level access and above, to change arbitrary options on affected sites. This can be used to enable new user registration and set the default role for new users to Administrator.
| CWE | CWE-862 |
| Vendor | xootix |
| Product | waitlist woocommerce ( back in stock notifier ) |
| Published | Jun 6, 2024 |
| Last Updated | Apr 8, 2026 |
Stay Ahead of the Next One
Get instant alerts for xootix waitlist woocommerce ( back in stock notifier )
Be the first to know when new high vulnerabilities affecting xootix waitlist woocommerce ( back in stock notifier ) are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Affected Versions
xootix / Waitlist Woocommerce ( Back in stock notifier )
0 โค 2.6
xootix / OTP Login & Register Woocommerce
0 โค 2.6.1
xootix / Side Cart Woocommerce | Woocommerce Cart
2.5
xootix / Login & Register Customizer โ Popup | Slider | Inline | WooCommerce
2.7.1 โค 2.7.2
References
wordfence.com: https://www.wordfence.com/threat-intel/vulnerabilities/id/005a27c6-b9eb-466c-b0c3-ce52c25bb321?source=cve plugins.trac.wordpress.org: https://plugins.trac.wordpress.org/browser/easy-login-woocommerce/trunk/includes/xoo-framework/admin/class-xoo-admin-settings.php#L83 plugins.trac.wordpress.org: https://plugins.trac.wordpress.org/changeset/3093994/ plugins.trac.wordpress.org: https://plugins.trac.wordpress.org/browser/side-cart-woocommerce/trunk/includes/xoo-framework/admin/class-xoo-admin-settings.php#L83 plugins.trac.wordpress.org: https://plugins.trac.wordpress.org/changeset/3111541/ plugins.trac.wordpress.org: https://plugins.trac.wordpress.org/changeset/3115392/mobile-login-woocommerce/trunk?contextall=1&old=3084918&old_path=%2Fmobile-login-woocommerce%2Ftrunk plugins.trac.wordpress.org: https://plugins.trac.wordpress.org/changeset/3117332/
Credits
AmrAwad