跳转到帖子

Wordpress Plugin WooCommerce Payments Unauthenticated Admin Creation

recommended_posts

发布于
  • Members

Wordpress Plugin WooCommerce Payments Unauthenticated Admin Creation

Disclosed
03/22/2023
Created
07/11/2023

Description

WooCommerce-Payments plugin for Wordpress versions 4.8', '4.8.2, 4.9', '4.9.1, 5.0', '5.0.4, 5.1', '5.1.3, 5.2', '5.2.2, 5.3', '5.3.1, 5.4', '5.4.1, 5.5', '5.5.2, and 5.6', '5.6.2 contain an authentication bypass by specifying a valid user ID number within the X-WCPAY-PLATFORM-CHECKOUT-USER header. With this authentication bypass, a user can then use the API to create a new user with administrative privileges on the target WordPress site IF the user ID selected corresponds to an administrator account.

Author(s)

  • h00die
  • Michael Mazzolini
  • Julien Ahrens

Development

  • Source Code
  • History
  • 查看数 702
  • 已创建
  • 最后回复