PT-2026-64226 · WordPress · Wpify Woo
CVSS v3.1
8.0
High
| Vector | AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Wpify Woo versions prior to 5.4.17
Description
The Wpify Woo plugin for WordPress allows authenticated users with Shop Manager-level access or higher to escalate their privileges to Administrator. This occurs because the
SettingsApi::save option() function in the REST endpoint 'POST /wp-json/wpify-woo/v1/option' passes the option and data parameters directly to the update option() function without sanitizing the values or using an allowlist for option names. Consequently, an attacker can overwrite arbitrary WordPress options, such as modifying default role to administrator, enabling users can register, or disabling security plugins through the active plugins option.Recommendations
Update the plugin to a version later than 5.4.16.
Restrict access to the 'POST /wp-json/wpify-woo/v1/option' endpoint to minimize the risk of exploitation.
Fix
LPE
Improper Privilege Management
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Wpify Woo