Authentication vulnerability in Simpler Checkout 1.1.9

The Simpler Checkout plugin for WordPress has a security issue in versions 0.7.0 to 1.1.9. This is because the plugin does not properly check a user’s identity before allowing them to log in as an admin through the simplerwc_woocommerce_order_created() function. This means that someone who is not logged in can pretend to be another user based on their order ID, which could potentially give them access to an administrator account if the site admin has placed a test order.

Detected in:

Simpler Checkout fixed vulnerable versions: >= 0.7.0 <= 1.1.13

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.