PT-2024-39942 · WordPress · Woocommerce Order Proposal

·

CVE-2024-9927

·

Published

2024-10-23

·

Updated

2024-10-25

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions WooCommerce Order Proposal plugin for WordPress versions up to and including 2.0.5
Description The issue is due to the improper implementation of the allow payment without login function, making it possible for authenticated attackers with Shop Manager-level access and above to log in to WordPress as an arbitrary user account, including administrators, via order proposal.
Recommendations For versions up to and including 2.0.5, update to a version later than 2.0.5 to resolve the issue. As a temporary workaround, consider restricting access to the allow payment without login function until a patch is available.

Fix

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-9927

Affected Products

Woocommerce Order Proposal