WPC Shop as a Customer for WooCommerce [wpc-shop-as-customer] < 1.2.9
unknown
[en] The WPC Shop as a Customer for WooCommerce plugin for WordPress is vulnerable to account takeover and privilege escalation in all versions up to, and including, 1.2.8. This is due to the 'generate_key' function not producing a sufficiently random value. This makes it possible for authenticated attackers, with Subs...
- Affected:
- up to 1.2.9
- Fixed in:
- 1.2.9
- Disclosed:
- Dec 18, 2024
CVE-2024-12432 on NVD →
WPC Shop as a Customer for WooCommerce <= 1.2.8 - Authentication Bypass Due to Insufficiently Unique Key
high
The WPC Shop as a Customer for WooCommerce plugin for WordPress is vulnerable to account takeover and privilege escalation in all versions up to, and including, 1.2.8. This is due to the 'generate_key' function not producing a sufficiently random value. This makes it possible for authenticated attackers, with Subscribe...
- CVSS:
- 8.1
- Affected:
- up to 1.2.8
- Fixed in:
- 1.2.9
- Disclosed:
- Dec 17, 2024
CVE-2024-12432 on NVD →
WPC Shop as a Customer for WooCommerce [wpc-shop-as-customer] < 1.2.7
unknown
[en] Deserialization of Untrusted Data vulnerability in WPClever WPC Shop as a Customer for WooCommerce allows Object Injection.This issue affects WPC Shop as a Customer for WooCommerce: from n/a through 1.2.6.
- Affected:
- up to 1.2.7
- Fixed in:
- 1.2.7
- Disclosed:
- Oct 28, 2024
CVE-2024-50416 on NVD →
WPC Shop as a Customer for WooCommerce <= 1.2.6 - Authenticated (Subscriber+) PHP Object Injection
high
The WPC Shop as a Customer for WooCommerce plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.2.6 via deserialization of untrusted input. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject a PHP Object. No known POP chain is...
- CVSS:
- 8.8
- Affected:
- up to 1.2.6
- Fixed in:
- 1.2.7
- Disclosed:
- Oct 24, 2024
CVE-2024-50416 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database