PT-2024-38035 · WordPress · Woocommerce Pdf Vouchers

István Márton

·

Published

2024-07-24

·

Updated

2024-07-24

·

CVE-2024-7027

CVSS v3.1

7.3

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions WooCommerce - PDF Vouchers plugin for WordPress versions up to, and including, 4.9.3
Description The issue is related to authentication bypass due to insufficient verification of the user during a QR code login. This allows unauthenticated attackers to log in as any existing Voucher Vendor user if they have access to the user id.
Recommendations For versions up to, and including, 4.9.3, update to a version higher than 4.9.3 to resolve the issue. As a temporary workaround, consider restricting access to the QR code login feature until a patch is available. Avoid using the user id in the affected login process to minimize the risk of exploitation.

Fix

Authentication Bypass Using an Alternate Path or Channel

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-7027

Affected Products

Woocommerce Pdf Vouchers