PT-2025-14091 · WordPress · Sms Alert Order Notifications

Lucio Sá

·

Publicado

2025-04-01

·

Atualizado

2025-04-05

·

CVE-2024-13553

CVSS v3.1

9.8

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions SMS Alert Order Notifications – WooCommerce plugin for WordPress versions up to, and including, 3.7.9
Description The issue allows for privilege escalation via account takeover. This is due to the plugin using the Host header to determine if it is in a playground environment, making it possible for unauthenticated attackers to spoof the Host header, set the OTP code to "1234", and authenticate as any user, including administrators.
Recommendations For versions up to, and including, 3.7.9, update to a version higher than 3.7.9 to resolve the issue. As a temporary workaround, consider restricting access to the plugin's functionality to minimize the risk of exploitation.

Correção

LPE

Missing Authentication

Authentication Bypass Using an Alternate Path or Channel

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2024-13553

Produtos afetados

Sms Alert Order Notifications