Description
The Simpler Checkout plugin for WordPress is vulnerable to Authentication Bypass in versions 0.7.0 to 1.1.9. This is due to the plugin not properly verifying a user's identity prior to logging them in as an admin through the simplerwc_woocommerce_order_created() function. This makes it possible for unauthenticated attackers to log in as other users based on their order ID, which can be an administrator if a site admin has placed a test order.
Problem types
CWE-288 Authentication Bypass Using an Alternate Path or Channel
Product status
0.7.0
Timeline
2025-08-22: | Disclosed |
Credits
Kenneth Dunn
References
www.wordfence.com/...-bd12-44b1-9bc5-1a5ec332b000?source=cve
plugins.trac.wordpress.org/.../tags/1.1.9/includes/hooks.php