Privilege Escalation and Account Takeover in WooCommerce Plugin for WordPress
CVE-2024-12432

8.1HIGH

Key Information:

Vendor

WordPress

Vendor
CVE Published:
18 December 2024

What is CVE-2024-12432?

CVE-2024-12432 identifies a severe security vulnerability in the WPC Shop as a Customer for WooCommerce plugin for WordPress, affecting all versions up to and including 1.2.8. This vulnerability arises from the 'generate_key' function, which fails to generate a sufficiently random value. Consequently, this weakness allows authenticated attackers with Subscriber-level access and above to exploit the ajax_login() function, enabling them to create a unique key that could grant unauthorized access as site administrators. Organizations using this plugin should take immediate steps to update to a patched version to mitigate risks related to account takeover and privilege escalation.

Affected Version(s)

WPC Shop as a Customer for WooCommerce 0 <= 1.2.8

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

.