Woocommerce Customers Manager <= 26.4 - Authenticated Account Creation and Privilege Escalation

2021-02-24 00:00
John Castro

Strategic Overview

Status
Patched in 26.5
Affected Version< 26.5
CVSS8.8High
CVEN/A
View all WooCommerce Customers Manager vulnerabilities

Vulnerability Overview

The Woocommerce Customers Manager plugin for WordPress is vulnerable to authorization bypass due to a missing capability checks in the user import in versions up to, and including, 26.4. This makes it possible for Subscriber-level attackers to import arbitrary user information to create or update administrative accounts.

Technical Analysis

REMEDIATION: Update to version 26.5, or a newer patched version --- IDENTIFIER: CWE-266 (Incorrect Privilege Assignment) A product incorrectly assigns a privilege to a particular actor, creating an unintended sphere of control for that actor.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C