Biometric Login for WooCommerce <= 1.0.3 - Unauthenticated Privilege Escalation
criticalThe Biometric Login for WooCommerce plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 1.0.3. This is due to missing validation of WebAuthn authentication requests. This makes it possible for unauthenticated attackers to take over accounts that have WebAuthn enabled on affected...
- CVSS:
- 9.8
- Affected:
- up to 1.0.3
- Fixed in:
- 1.0.4
- Disclosed:
- Aug 8, 2023