PT-2025-14091 · WordPress · Sms Alert Order Notifications
Lucio Sá
·
Publicado
2025-04-01
·
Atualizado
2025-04-05
·
CVE-2024-13553
CVSS v3.1
9.8
Crítica
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
SMS Alert Order Notifications – WooCommerce plugin for WordPress versions up to, and including, 3.7.9
Description
The issue allows for privilege escalation via account takeover. This is due to the plugin using the Host header to determine if it is in a playground environment, making it possible for unauthenticated attackers to spoof the Host header, set the OTP code to "1234", and authenticate as any user, including administrators.
Recommendations
For versions up to, and including, 3.7.9, update to a version higher than 3.7.9 to resolve the issue. As a temporary workaround, consider restricting access to the plugin's functionality to minimize the risk of exploitation.
Correção
LPE
Missing Authentication
Authentication Bypass Using an Alternate Path or Channel
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Sms Alert Order Notifications