CVE-2024-12432: WPC Shop as a Customer for WooCommerce <= 1.2.8 - Authentication Bypass Due to Insufficiently Unique Key
The WPC Shop as a Customer for WooCommerce plugin for WordPress is vulnerable to account takeover and privilege escalation in all versions up to, and including, 1.2.8. This is due to the 'generatekey' function not producing a sufficiently random value. This makes it possible for authenticated attackers, with Subscriber-level access and above, to log in as site administrators, granted they have triggered the ajaxlogin() function which generates a unique key that can be used to log in.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-12432?
CVE-2024-12432 is considered a high severity vulnerability, leading to possible account takeover and privilege escalation.
How do I fix CVE-2024-12432?
To fix CVE-2024-12432, update the WPC Shop as a Customer for WooCommerce plugin to version 1.2.9 or later.
Who is affected by CVE-2024-12432?
CVE-2024-12432 affects all users of the WPC Shop as a Customer for WooCommerce plugin versions up to and including 1.2.8.
What causes CVE-2024-12432?
CVE-2024-12432 is caused by the 'generate_key' function not producing a sufficiently random value, which jeopardizes user account security.
Is CVE-2024-12432 being actively exploited?
As of now, there are no confirmed reports of exploitation of CVE-2024-12432, but its high severity warrants immediate action.