PT-2026-65739 · Holest+1 · Spreadsheet Price Changer For Woocommerce/Wp E-Commerce – Light+1
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Spreadsheet Price Changer for WooCommerce and WP E-commerce – Light versions prior to 2.4.38
Description
The plugin contains a missing authorization flaw within the
user filter() function. This allows unauthenticated attackers to create administrative accounts.Recommendations
Update the plugin to version 2.4.38 or later.
As a temporary workaround, consider disabling the
user filter() function until the update is applied.Fix
DoS
Incorrect Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Spreadsheet Price Changer For Woocommerce/Wp E-Commerce – Light
Excel-Like-Price-Change-For-Woocommerce-And-Wp-E-Commerce-Light