Authentication vulnerability in WooCommerce Order Proposal 2.0.5

The WooCommerce Order Proposal plugin for WordPress has a security issue that allows attackers to gain higher levels of access than they should have. This can happen when using the order proposal feature and is present in versions 2.0.5 and below. The problem is caused by a mistake in how the “allow_payment_without_login” function was set up. This makes it possible for someone with Shop Manager or higher access to log in as any user, even administrators.

Detected in:

WooCommerce Order Proposal fixed vulnerable versions: >= * <= 2.0.5

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.