Woocommerce Customers Manager <= 26.4 - Authenticated Account Creation and Privilege Escalation
2021-02-24 00:00
John CastroStrategic Overview
StatusPatched in 26.5
Affected PluginWooCommerce Customers Manager
Affected Version
< 26.5CVSS8.8High
CVE
N/AVulnerability Overview
The Woocommerce Customers Manager plugin for WordPress is vulnerable to authorization bypass due to a missing capability checks in the user import in versions up to, and including, 26.4. This makes it possible for Subscriber-level attackers to import arbitrary user information to create or update administrative accounts.
Technical Analysis
REMEDIATION: Update to version 26.5, or a newer patched version --- IDENTIFIER: CWE-266 (Incorrect Privilege Assignment) A product incorrectly assigns a privilege to a particular actor, creating an unintended sphere of control for that actor.
External References
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C