Authenticated Attackers Can Escalate Privileges in WooCommerce Order Proposal Plugin
CVE-2024-9927
7.2HIGH
What is CVE-2024-9927?
The WooCommerce Order Proposal plugin for WordPress contains a vulnerability that enables privilege escalation through the order proposal process. This flaw exists in all versions up to and including 2.0.5, stemming from an improper implementation of the allow_payment_without_login function. Authenticated attackers with Shop Manager-level access or higher can exploit this issue, granting them the ability to log in as any user, including those with administrative privileges. Website administrators should ensure prompt updates and implement additional security measures to mitigate potential risks arising from this vulnerability.
Affected Version(s)
WooCommerce Order Proposal * <= 2.0.5