CVE-2024-37210
Deferred Deferred - Pending Action
Missing Authorization in AliNext E-Commerce Plugin

Publication date: 2026-06-17

Last updated on: 2026-06-17

Assigner: Patchstack

Description
Missing Authorization vulnerability in ali2woo AliNext allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects AliNext: from n/a through 3.3.5.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2026-06-17
Last Modified
2026-06-17
Generated
2026-06-17
AI Q&A
2026-06-17
EPSS Evaluated
N/A
NVD
EUVD
Affected Vendors & Products
Showing 3 associated CPEs
Vendor Product Version / Range
alinext ali2woo From 3.0.0 (inc) to 3.3.5 (inc)
alinext ali2woo 3.3.5
alinext ali2woo 3.3.7
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-862 The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
Attack-Flow Graph
AI Quick Actions
Instant insights powered by AI
Executive Summary

CVE-2024-37210 is a Missing Authorization vulnerability in the AliNext WordPress plugin (versions 3.3.5 and below). It is a Broken Access Control issue that allows unprivileged users, such as subscribers, to perform actions that normally require higher privileges. This happens because the plugin lacks proper authorization, authentication, or nonce token checks.

Impact Analysis

This vulnerability can allow attackers to perform unauthorized actions on websites using the vulnerable AliNext plugin. Since unprivileged users can escalate their privileges, attackers could exploit this flaw to compromise thousands of websites in mass-exploitation campaigns, potentially leading to unauthorized changes or access to sensitive parts of the site.

Mitigation Strategies

To mitigate the vulnerability in the AliNext WordPress plugin (versions 3.3.5 and below), users should immediately update the plugin to version 3.3.7 or later.

Until the update can be applied, users are advised to use Patchstack’s mitigation rule to block attacks targeting this vulnerability.

Compliance Impact

The vulnerability in AliNext allows unprivileged users to perform higher-privileged actions due to missing authorization checks, which can lead to unauthorized access to sensitive data or functionality.

Such unauthorized access could potentially result in non-compliance with standards and regulations like GDPR or HIPAA, which require strict access controls to protect personal and sensitive information.

However, the provided information does not explicitly detail the impact on compliance with these regulations.

Chat Assistant
Ask questions about this CVE
Hi! I’m here to help you understand CVE-2024-37210. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70
EPSS Chart