PT-2026-65739 · Holest · Spreadsheet Price Changer For Woocommerce/Wp E-Commerce – Light
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
The Spreadsheet Price Changer for WooCommerce and WP E-commerce – Light plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 2.4.37 vi the user filter function. This makes it possible for unauthenticated attackers to create admin accounts.
Fix
Incorrect Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Spreadsheet Price Changer For Woocommerce/Wp E-Commerce – Light