---
id: CVE-2024-1310
title: >-
  The WooCommerce WordPress plugin before 8.6 does not prevent users with at
  least the contributor role from leaking products they shouldn't have access to
summary: >-
  The WooCommerce WordPress plugin before 8.6 does not prevent users with at
  least the contributor role from leaking products they shouldn't have access
  to. (e.g. private, draft and trashed products)
severity: medium
cvss: 4.9
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N'
vendor: automattic
product: woocommerce
affected:
  - woocommerce < 8.6.0
patched:
  - woocommerce 8.6.0
published: '2024-04-15'
updated: '2026-07-20'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2024-1310'
references:
  - url: 'https://wpscan.com/vulnerability/a7735feb-876e-461c-9a56-ea6067faf277/'
    label: contact@wpscan.com
  - url: 'https://wpscan.com/vulnerability/a7735feb-876e-461c-9a56-ea6067faf277/'
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
epss: 0.00686
epssPercentile: 0.50516
ingestedAt: '2026-07-20T19:42:47.757Z'
---

## Overview

The WooCommerce WordPress plugin before 8.6 does not prevent users with at least the contributor role from leaking products they shouldn't have access to. (e.g. private, draft and trashed products)

## Affected

- `woocommerce < 8.6.0`

## Remediation

Upgrade past the affected range:

- `woocommerce 8.6.0`
