Security Advisory

CVE-2024-1516

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2024-02-28 08:33:11
Last updated 2026-04-08 17:15:59
Assigner Wordfence
State PUBLISHED

Description

The WP eCommerce plugin for WordPress is vulnerable to unauthorized arbitrary post creation due to a missing capability check on the check_for_saas_push() function in all versions up to, and including, 3.15.1. This makes it possible for unauthenticated attackers to create arbitrary posts with arbitrary content.