QID 730856

Date Published: 2023-07-27

QID 730856: WordPress Plugin WooCommerce Payments Authentication Bypass and Privilege Escalation Vulnerability

WordPress Plugin WooCommerce Payments is a payment solution fully integrated to Woo.

The WooCommerce Payments plugin is vulnerable to authentication bypass and privilege escalation vulnerability, this allows an unauthenticated attacker to send requests on behalf of an elevated user, like administrator.

Affected Versions:
WordPress Plugin WooCommerce Payments versions from 4.8.0 prior to 5.6.2

QID Detection Logic:
This unauthenticated detection depends on the BlindElephant engine to detect the vulnerable version of the WooCommerce Payments WordPress plugin.

Successful exploitation of this vulnerability may allows a remote, unauthenticated attacker to gain admin access on a site that has the affected version of the plugin activated.

  • CVSS V3 rated as Critical - 9.8 severity.
  • CVSS V2 rated as High - 7.5 severity.
  • Solution
    Customers are advised to upgrade to WordPress WooCommerce Payments Plugin version 5.6.2 or later version to remediate this vulnerability.
    Vendor References

    CVEs related to QID 730856

    Software Advisories
    Advisory ID Software Component Link
    WooCommerce Payments Plugin Release Notes URL Logo wordpress.org/plugins/woocommerce-payments/#developers