CVE-2024-9927: WooCommerce Order Proposal <= 2.0.5 - Authenticated (Shop Manager+) Privilege Escalation via Order Proposal
The WooCommerce Order Proposal plugin for WordPress is vulnerable to privilege escalation via order proposal in all versions up to and including 2.0.5. This is due to the improper implementation of allowpaymentwithoutlogin function. This makes it possible for authenticated attackers, with Shop Manager-level access and above, to log in to WordPress as an arbitrary user account, including administrators.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-9927?
The severity of CVE-2024-9927 is classified as high due to its potential for privilege escalation.
How do I fix CVE-2024-9927?
To fix CVE-2024-9927, upgrade the WooCommerce Order Proposal plugin to version 2.0.6 or later.
Who is affected by CVE-2024-9927?
CVE-2024-9927 affects all versions of the WooCommerce Order Proposal plugin up to and including version 2.0.5.
What kind of attack does CVE-2024-9927 allow?
CVE-2024-9927 allows authenticated attackers to escalate privileges through the improper implementation of the allow_payment_without_login function.
Is the WooCommerce Order Proposal plugin still safe to use after CVE-2024-9927?
The WooCommerce Order Proposal plugin can be safe to use if it is updated to version 2.0.6 or later to mitigate the vulnerability.