PT-2025-1795 · Payu · Payu Commercepro Plugin For Wordpress

Wesley

·

Published

2025-01-07

·

Updated

2025-01-12

·

CVE-2024-12264

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions PayU CommercePro Plugin for WordPress versions up to, and including, 3.8.3
Description The issue is due to the /wp-json/payu/v1/generate-user-token and /wp-json/payu/v1/get-shipping-cost REST API endpoints not properly verifying a user's identity prior to setting the user's ID and auth cookies. This makes it possible for unauthenticated attackers to create new administrative user accounts.
Recommendations For PayU CommercePro Plugin for WordPress versions up to, and including, 3.8.3, consider disabling the /wp-json/payu/v1/generate-user-token and /wp-json/payu/v1/get-shipping-cost API endpoints until a patch is available. Restrict access to these endpoints to minimize the risk of exploitation. Avoid using these endpoints until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

LPE

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-12264

Affected Products

Payu Commercepro Plugin For Wordpress