WooCommerce <= 4.6.1 & WooCommerce Blocks <= 3.7.0 - Settings Bypass leading to Account Creation

2020-11-05 00:00
Anonymous

Strategic Overview

Status
Patched in 4.6.2
Affected PluginWooCommerce
Affected Version< 4.6.2
CVSS6.5Medium
CVEN/A
View all WooCommerce vulnerabilities

Vulnerability Overview

The WooCommerce plugin for WordPress is vulnerable to unauthorized user account creation during checkout even when the “Allow customers to create an account during checkout” setting is disabled. was disabled due to missing authorization checks in versions up to and including 4.6.1. The WooCommerce Blocks plugin for WordPress is vulnerable to the same issue in versions up to, and including, 3.7.1.

Technical Analysis

REMEDIATION: Update to version 4.6.2, or a newer patched version --- IDENTIFIER: CWE-862 (Missing Authorization) The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C