CVE-2024-12432
CVSS 3.1 Score 8.1 of 10 (high)
Details
Published Dec 18, 2024
CWE ID 330
Summary
CVE-2024-12432 is a vulnerability affecting the WPC Shop as a Customer for WooCommerce plugin for WordPress. This issue exposes both account takeover and privilege escalation risks, with versions up to 1.2.8 being vulnerable. The root cause lies in the 'generate_key' function, which produces insufficiently random values. Consequently, authenticated attackers with Subscriber-level access or higher can exploit this flaw to gain administrative privileges by manipulating unique keys generated through the ajax_login() function.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.