Privilege Escalation and Account Takeover in WooCommerce Plugin for WordPress
CVE-2024-12432
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 18 December 2024
What is CVE-2024-12432?
CVE-2024-12432 identifies a severe security vulnerability in the WPC Shop as a Customer for WooCommerce plugin for WordPress, affecting all versions up to and including 1.2.8. This vulnerability arises from the 'generate_key' function, which fails to generate a sufficiently random value. Consequently, this weakness allows authenticated attackers with Subscriber-level access and above to exploit the ajax_login() function, enabling them to create a unique key that could grant unauthorized access as site administrators. Organizations using this plugin should take immediate steps to update to a patched version to mitigate risks related to account takeover and privilege escalation.
Affected Version(s)
WPC Shop as a Customer for WooCommerce 0 <= 1.2.8