PT-2025-34507 · WordPress · Simpler Checkout
Kenneth Dunn
·
Published
2025-08-23
·
Updated
2025-08-23
·
CVE-2025-7642
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
Simpler Checkout versions 0.7.0 through 1.1.9
Description:
The Simpler Checkout plugin for WordPress is susceptible to authentication bypass. The plugin does not properly verify a user’s identity before granting access as an administrator through the
simplerwc woocommerce order created() function. This allows unauthenticated attackers to log in as other users, potentially including administrators, by exploiting order IDs.Recommendations:
versions prior to 0.7.0
versions after 1.1.9
Fix
Authentication Bypass Using an Alternate Path or Channel
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Simpler Checkout