Description
The EasyCommerce – AI-Powered, Fast & Beautiful WordPress Ecommerce Plugin plugin for WordPress is vulnerable to Privilege Escalation in versions 0.9.0-beta2 to 1.5.0. This is due to the /easycommerce/v1/orders REST API endpoint not properly restricting the ability for users to select roles during registration. This makes it possible for unauthenticated attackers to gain administrator-level access to a vulnerable site.
Problem types
CWE-269 Improper Privilege Management
Product status
* (semver)
Timeline
| 2025-11-10: | Disclosed |
Credits
Kenneth Dunn
References
www.wordfence.com/...-abc1-410c-b315-118746ff235a?source=cve
wordpress.org/plugins/easycommerce/