Shop as a Customer for WooCommerce <= 1.2.3 - Authenticated (Shop Manager+) Privilege Escalation
high
The Shop as a Customer for WooCommerce plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 1.2.3. This makes it possible for authenticated attackers, with WooCommerce Shop Manager permissions or above, to log in as any user, such as an administrator.
- CVSS:
- 8.8
- Affected:
- up to 1.2.3
- Fixed in:
- 1.2.4
- Disclosed:
- Jul 31, 2023
Shop as a Customer for WooCommerce <= 1.1.7 - Authenticated (Subscriber+) Privilege Escalation
high
The Shop as a Customer for WooCommerce plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 1.1.7. This makes it possible for authenticated attackers, with subscriber-level permissions or above, to log in as any user, such as an administrator.
- CVSS:
- 8.8
- Affected:
- up to 1.1.7
- Fixed in:
- 1.1.8
- Disclosed:
- Jul 31, 2023
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database