plugin

Wpc Shop As Customer Vulnerabilities

4 known security issues reported for the Wpc Shop As Customer WordPress plugin. Most recent disclosed Dec 18, 2024.

2 high

Running Wpc Shop As Customer on your site? Check whether your installed version is affected.

Scan your site free

WPC Shop as a Customer for WooCommerce [wpc-shop-as-customer] < 1.2.9

unknown

[en] The WPC Shop as a Customer for WooCommerce plugin for WordPress is vulnerable to account takeover and privilege escalation in all versions up to, and including, 1.2.8. This is due to the 'generate_key' function not producing a sufficiently random value. This makes it possible for authenticated attackers, with Subs...

Affected:
up to 1.2.9
Fixed in:
1.2.9
Disclosed:
Dec 18, 2024

CVE-2024-12432 on NVD →

WPC Shop as a Customer for WooCommerce <= 1.2.8 - Authentication Bypass Due to Insufficiently Unique Key

high

The WPC Shop as a Customer for WooCommerce plugin for WordPress is vulnerable to account takeover and privilege escalation in all versions up to, and including, 1.2.8. This is due to the 'generate_key' function not producing a sufficiently random value. This makes it possible for authenticated attackers, with Subscribe...

CVSS:
8.1
Affected:
up to 1.2.8
Fixed in:
1.2.9
Disclosed:
Dec 17, 2024

CVE-2024-12432 on NVD →

WPC Shop as a Customer for WooCommerce [wpc-shop-as-customer] < 1.2.7

unknown

[en] Deserialization of Untrusted Data vulnerability in WPClever WPC Shop as a Customer for WooCommerce allows Object Injection.This issue affects WPC Shop as a Customer for WooCommerce: from n/a through 1.2.6.

Affected:
up to 1.2.7
Fixed in:
1.2.7
Disclosed:
Oct 28, 2024

CVE-2024-50416 on NVD →

WPC Shop as a Customer for WooCommerce <= 1.2.6 - Authenticated (Subscriber+) PHP Object Injection

high

The WPC Shop as a Customer for WooCommerce plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.2.6 via deserialization of untrusted input. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject a PHP Object. No known POP chain is...

CVSS:
8.8
Affected:
up to 1.2.6
Fixed in:
1.2.7
Disclosed:
Oct 24, 2024

CVE-2024-50416 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database