Abandoned Cart Lite for WooCommerce <= 5.15.1 - Authentication Bypass
82Vexday Risk Score
Priorize a correção. Ela exploração observada pelo VulnCheck e tem prova de conceito pública.
ssvc Actcvss 9.8epss 43%
da publicação à arma1 dias
Publicada no NVD8 de jun.
1ª PoC+1d
VulnCheck+15d
probabilidade de exploração
43%top 1% das CVEs
exploração observada
simVulnCheck
4 exploit(s) público(s)
The Abandoned Cart Lite for WooCommerce plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 5.14.2. This is due to insufficient encryption on the user being supplied during the abandoned cart link decode through the plugin. This allows unauthenticated attackers to log in as users who have abandoned the cart, who are typically customers. Further security hardening was introduced in version 5.15.1 that ensures sites are no longer vulnerable through historical check-out links, and additional hardening was introduced in version 5.15.2 that ensured null key values wouldn't permit the authentication bypass.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Produtos afetados
tychesoftwares · Abandoned Cart Lite for WooCommercePoCs públicas encontradas — 4
githubgithub.com/Ayantaker/CVE-2023-2986★ 6githubgithub.com/Alucard0x1/CVE-2023-2986★ 0vulncheckvulncheck.com/xdb/3e03ea94d090não verificadovulncheckvulncheck.com/xdb/2b7e1262b7d5não verificado⚠ Recursos públicos, para você avaliar a exposição de sistemas que controla ou está autorizado a testar. Teste apenas com autorização.
Referências
https://github.com/Ayantaker/CVE-2023-2986https://github.com/TycheSoftwares/woocommerce-abandoned-cart/pull/885#issuecomment-1601813615https://plugins.trac.wordpress.org/browser/woocommerce-abandoned-cart/trunk/woocommerce-ac.php#L1815https://plugins.trac.wordpress.org/browser/woocommerce-abandoned-cart/trunk/woocommerce-ac.php?rev=2916178#L1800https://plugins.trac.wordpress.org/changeset/2922242/https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=2925274%40woocommerce-abandoned-cart&new=2925274%40woocommerce-abandoned-cart&sfp_email=&sfph_mail=https://www.wordfence.com/blog/2023/06/tyche-softwares-addresses-authentication-bypass-vulnerability-in-abandoned-cart-lite-for-woocommerce-wordpress-plugin/https://www.wordfence.com/threat-intel/vulnerabilities/id/68052614-204f-4237-af0e-4b8210ebd59f?source=cve