Search
Find a vulnerability
Search criteria
6 vulnerabilities found for WPC Shop as a Customer for WooCommerce by wpclever
CVE-2026-95687 (GCVE-0-2026-95687)
Vulnerability from nvd – Published: 2026-10-01 08:28 – Updated: 2026-10-01 08:28
VLAI
EPSS
VEX
Title
WPC Shop as a Customer for WooCommerce <= 2.0.0 - Authenticated (Subscriber+) Privilege Escalation via Missing Role Check on Target User to wpcsa_login AJAX Endpoint
Summary
The WPC Shop as a Customer for WooCommerce plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 2.0.0 This is due to the plugin not properly validating the target user's role prior to issuing a new authentication session, allowing an authenticated attacker to log in as any WordPress Administrator by directly supplying an Administrator's user ID to the wpcsa_login endpoint and receiving a full Administrator session cookie without supplying the Administrator's password. This makes it possible for authenticated attackers to perform a direct session takeover, gaining full Administrator-level access to the site.
Severity
8.8 (High)
CWE
- CWE-269 - Improper Privilege Management
Assigner
References
6 references
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| wpclever | WPC Shop as a Customer for WooCommerce |
Affected:
0 , ≤ 2.0.0
(semver)
|
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "WPC Shop as a Customer for WooCommerce",
"vendor": "wpclever",
"versions": [
{
"lessThanOrEqual": "2.0.0",
"status": "affected",
"version": "0",
"versionType": "semver"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "clever"
}
],
"descriptions": [
{
"lang": "en",
"value": "The WPC Shop as a Customer for WooCommerce plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 2.0.0 This is due to the plugin not properly validating the target user\u0027s role prior to issuing a new authentication session, allowing an authenticated attacker to log in as any WordPress Administrator by directly supplying an Administrator\u0027s user ID to the wpcsa_login endpoint and receiving a full Administrator session cookie without supplying the Administrator\u0027s password. This makes it possible for authenticated attackers to perform a direct session takeover, gaining full Administrator-level access to the site."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 8.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-269",
"description": "CWE-269 Improper Privilege Management",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-01T08:28:43.728Z",
"orgId": "b15e7b5b-3da4-40ae-a43c-f7aa60e62599",
"shortName": "Wordfence"
},
"references": [
{
"url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/539cdee3-78bc-42a2-9c34-0f7d46f95d16?source=cve"
},
{
"url": "https://plugins.trac.wordpress.org/browser/wpc-shop-as-customer/tags/1.3.6/wpc-shop-as-customer.php#L253"
},
{
"url": "https://plugins.trac.wordpress.org/browser/wpc-shop-as-customer/tags/1.3.6/wpc-shop-as-customer.php#L228"
},
{
"url": "https://plugins.trac.wordpress.org/browser/wpc-shop-as-customer/tags/1.3.6/wpc-shop-as-customer.php#L96"
},
{
"url": "https://plugins.trac.wordpress.org/changeset?reponame=\u0026new=3708414%40wpc-shop-as-customer%2Ftags%2F2.0.1\u0026old=3708360%40wpc-shop-as-customer%2Ftags%2F2.0.0"
},
{
"url": "https://plugins.trac.wordpress.org/changeset/3708414/wpc-shop-as-customer/trunk/wpc-shop-as-customer.php"
}
],
"timeline": [
{
"lang": "en",
"time": "2026-09-22T14:29:24.000Z",
"value": "Vendor Notified"
},
{
"lang": "en",
"time": "2026-09-30T19:45:46.000Z",
"value": "Disclosed"
}
],
"title": "WPC Shop as a Customer for WooCommerce \u003c= 2.0.0 - Authenticated (Subscriber+) Privilege Escalation via Missing Role Check on Target User to wpcsa_login AJAX Endpoint"
}
},
"cveMetadata": {
"assignerOrgId": "b15e7b5b-3da4-40ae-a43c-f7aa60e62599",
"assignerShortName": "Wordfence",
"cveId": "CVE-2026-95687",
"datePublished": "2026-10-01T08:28:43.728Z",
"dateReserved": "2026-09-22T14:14:09.896Z",
"dateUpdated": "2026-10-01T08:28:43.728Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2024-12432 (GCVE-0-2024-12432)
Vulnerability from nvd – Published: 2024-12-18 03:22 – Updated: 2026-04-08 16:33
VLAI
EPSS
VEX
Title
WPC Shop as a Customer for WooCommerce <= 1.2.8 - Authentication Bypass Due to Insufficiently Unique Key
Summary
The WPC Shop as a Customer for WooCommerce plugin for WordPress is vulnerable to account takeover and privilege escalation in all versions up to, and including, 1.2.8. This is due to the 'generate_key' function not producing a sufficiently random value. This makes it possible for authenticated attackers, with Subscriber-level access and above, to log in as site administrators, granted they have triggered the ajax_login() function which generates a unique key that can be used to log in.
Severity
8.1 (High)
SSVC
Exploitation: none
Automatable: no
Technical Impact: total
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2024-12-18 16:25 UTC
CWE
- CWE-330 - Use of Insufficiently Random Values
Assigner
References
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| wpclever | WPC Shop as a Customer for WooCommerce |
Affected:
0 , ≤ 1.2.8
(semver)
|
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2024-12432",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2024-12-18T16:25:17.044195Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2024-12-18T16:35:53.912Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "WPC Shop as a Customer for WooCommerce",
"vendor": "wpclever",
"versions": [
{
"lessThanOrEqual": "1.2.8",
"status": "affected",
"version": "0",
"versionType": "semver"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "Thanh Nam Tran"
}
],
"descriptions": [
{
"lang": "en",
"value": "The WPC Shop as a Customer for WooCommerce plugin for WordPress is vulnerable to account takeover and privilege escalation in all versions up to, and including, 1.2.8. This is due to the \u0027generate_key\u0027 function not producing a sufficiently random value. This makes it possible for authenticated attackers, with Subscriber-level access and above, to log in as site administrators, granted they have triggered the ajax_login() function which generates a unique key that can be used to log in."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 8.1,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-330",
"description": "CWE-330 Use of Insufficiently Random Values",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-04-08T16:33:10.637Z",
"orgId": "b15e7b5b-3da4-40ae-a43c-f7aa60e62599",
"shortName": "Wordfence"
},
"references": [
{
"url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/048625e8-10b7-418d-a13b-329f1d7e0171?source=cve"
},
{
"url": "https://plugins.trac.wordpress.org/changeset?sfp_email=\u0026sfph_mail=\u0026reponame=\u0026old=3208130%40wpc-shop-as-customer\u0026new=3208130%40wpc-shop-as-customer\u0026sfp_email=\u0026sfph_mail="
}
],
"timeline": [
{
"lang": "en",
"time": "2024-12-17T00:00:00.000Z",
"value": "Disclosed"
}
],
"title": "WPC Shop as a Customer for WooCommerce \u003c= 1.2.8 - Authentication Bypass Due to Insufficiently Unique Key"
}
},
"cveMetadata": {
"assignerOrgId": "b15e7b5b-3da4-40ae-a43c-f7aa60e62599",
"assignerShortName": "Wordfence",
"cveId": "CVE-2024-12432",
"datePublished": "2024-12-18T03:22:00.850Z",
"dateReserved": "2024-12-10T17:11:11.238Z",
"dateUpdated": "2026-04-08T16:33:10.637Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2024-50416 (GCVE-0-2024-50416)
Vulnerability from nvd – Published: 2024-10-28 11:30 – Updated: 2026-05-12 22:59
VLAI
EPSS
VEX
Title
WordPress WPC Shop as a Customer for WooCommerce plugin <= 1.2.6 - PHP Object Injection vulnerability
Summary
Deserialization of Untrusted Data vulnerability in WPClever WPC Shop as a Customer for WooCommerce wpc-shop-as-customer allows Object Injection.This issue affects WPC Shop as a Customer for WooCommerce: from n/a through <= 1.2.6.
Severity
8.8 (High)
SSVC
Exploitation: poc
Automatable: no
Technical Impact: total
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2024-10-28 12:00 UTC
CWE
- CWE-502 - Deserialization of Untrusted Data
Assigner
References
1 reference
| URL | Tags |
|---|---|
| https://patchstack.com/database/Wordpress/Plugin/… | vdb-entry |
Impacted products
2 products
| Vendor | Product | Version | |
|---|---|---|---|
| WPClever | WPC Shop as a Customer for WooCommerce |
Affected:
0 , ≤ 1.2.6
(custom)
|
|
| wpclever | wpc_shop_as_a_customer_for_woocommerce |
Affected:
0 , ≤ 1.2.6
(custom)
cpe:2.3:a:wpclever:wpc_shop_as_a_customer_for_woocommerce:*:*:*:*:*:*:*:* |
Date Public
2026-04-01 16:28
{
"containers": {
"adp": [
{
"affected": [
{
"cpes": [
"cpe:2.3:a:wpclever:wpc_shop_as_a_customer_for_woocommerce:*:*:*:*:*:*:*:*"
],
"defaultStatus": "unknown",
"product": "wpc_shop_as_a_customer_for_woocommerce",
"vendor": "wpclever",
"versions": [
{
"lessThanOrEqual": "1.2.6",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
}
],
"metrics": [
{
"other": {
"content": {
"id": "CVE-2024-50416",
"options": [
{
"Exploitation": "poc"
},
{
"Automatable": "no"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2024-10-28T12:00:41.522329Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-05-12T22:59:46.855Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"collectionURL": "https://wordpress.org/plugins",
"defaultStatus": "unaffected",
"packageName": "wpc-shop-as-customer",
"product": "WPC Shop as a Customer for WooCommerce",
"vendor": "WPClever",
"versions": [
{
"changes": [
{
"at": "1.2.7",
"status": "unaffected"
}
],
"lessThanOrEqual": "1.2.6",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "LVT-tholv2k | Patchstack Bug Bounty Program"
}
],
"datePublic": "2026-04-01T16:28:48.086Z",
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "Deserialization of Untrusted Data vulnerability in WPClever WPC Shop as a Customer for WooCommerce wpc-shop-as-customer allows Object Injection.\u003cp\u003eThis issue affects WPC Shop as a Customer for WooCommerce: from n/a through \u003c= 1.2.6.\u003c/p\u003e"
}
],
"value": "Deserialization of Untrusted Data vulnerability in WPClever WPC Shop as a Customer for WooCommerce wpc-shop-as-customer allows Object Injection.This issue affects WPC Shop as a Customer for WooCommerce: from n/a through \u003c= 1.2.6."
}
],
"impacts": [
{
"capecId": "CAPEC-586",
"descriptions": [
{
"lang": "en",
"value": "Object Injection"
}
]
}
],
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 8.8,
"baseSeverity": "HIGH",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "LOW",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-502",
"description": "Deserialization of Untrusted Data",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-04-28T16:10:28.559Z",
"orgId": "21595511-bba5-4825-b968-b78d1f9984a3",
"shortName": "Patchstack"
},
"references": [
{
"tags": [
"vdb-entry"
],
"url": "https://patchstack.com/database/Wordpress/Plugin/wpc-shop-as-customer/vulnerability/wordpress-wpc-shop-as-a-customer-for-woocommerce-plugin-1-2-6-php-object-injection-vulnerability?_s_id=cve"
}
],
"title": "WordPress WPC Shop as a Customer for WooCommerce plugin \u003c= 1.2.6 - PHP Object Injection vulnerability"
}
},
"cveMetadata": {
"assignerOrgId": "21595511-bba5-4825-b968-b78d1f9984a3",
"assignerShortName": "Patchstack",
"cveId": "CVE-2024-50416",
"datePublished": "2024-10-28T11:30:58.130Z",
"dateReserved": "2024-10-24T07:25:21.566Z",
"dateUpdated": "2026-05-12T22:59:46.855Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-95687 (GCVE-0-2026-95687)
Vulnerability from cvelistv5 – Published: 2026-10-01 08:28 – Updated: 2026-10-01 08:28
VLAI
EPSS
VEX
Title
WPC Shop as a Customer for WooCommerce <= 2.0.0 - Authenticated (Subscriber+) Privilege Escalation via Missing Role Check on Target User to wpcsa_login AJAX Endpoint
Summary
The WPC Shop as a Customer for WooCommerce plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 2.0.0 This is due to the plugin not properly validating the target user's role prior to issuing a new authentication session, allowing an authenticated attacker to log in as any WordPress Administrator by directly supplying an Administrator's user ID to the wpcsa_login endpoint and receiving a full Administrator session cookie without supplying the Administrator's password. This makes it possible for authenticated attackers to perform a direct session takeover, gaining full Administrator-level access to the site.
Severity
8.8 (High)
CWE
- CWE-269 - Improper Privilege Management
Assigner
References
6 references
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| wpclever | WPC Shop as a Customer for WooCommerce |
Affected:
0 , ≤ 2.0.0
(semver)
|
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "WPC Shop as a Customer for WooCommerce",
"vendor": "wpclever",
"versions": [
{
"lessThanOrEqual": "2.0.0",
"status": "affected",
"version": "0",
"versionType": "semver"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "clever"
}
],
"descriptions": [
{
"lang": "en",
"value": "The WPC Shop as a Customer for WooCommerce plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 2.0.0 This is due to the plugin not properly validating the target user\u0027s role prior to issuing a new authentication session, allowing an authenticated attacker to log in as any WordPress Administrator by directly supplying an Administrator\u0027s user ID to the wpcsa_login endpoint and receiving a full Administrator session cookie without supplying the Administrator\u0027s password. This makes it possible for authenticated attackers to perform a direct session takeover, gaining full Administrator-level access to the site."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 8.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-269",
"description": "CWE-269 Improper Privilege Management",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-01T08:28:43.728Z",
"orgId": "b15e7b5b-3da4-40ae-a43c-f7aa60e62599",
"shortName": "Wordfence"
},
"references": [
{
"url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/539cdee3-78bc-42a2-9c34-0f7d46f95d16?source=cve"
},
{
"url": "https://plugins.trac.wordpress.org/browser/wpc-shop-as-customer/tags/1.3.6/wpc-shop-as-customer.php#L253"
},
{
"url": "https://plugins.trac.wordpress.org/browser/wpc-shop-as-customer/tags/1.3.6/wpc-shop-as-customer.php#L228"
},
{
"url": "https://plugins.trac.wordpress.org/browser/wpc-shop-as-customer/tags/1.3.6/wpc-shop-as-customer.php#L96"
},
{
"url": "https://plugins.trac.wordpress.org/changeset?reponame=\u0026new=3708414%40wpc-shop-as-customer%2Ftags%2F2.0.1\u0026old=3708360%40wpc-shop-as-customer%2Ftags%2F2.0.0"
},
{
"url": "https://plugins.trac.wordpress.org/changeset/3708414/wpc-shop-as-customer/trunk/wpc-shop-as-customer.php"
}
],
"timeline": [
{
"lang": "en",
"time": "2026-09-22T14:29:24.000Z",
"value": "Vendor Notified"
},
{
"lang": "en",
"time": "2026-09-30T19:45:46.000Z",
"value": "Disclosed"
}
],
"title": "WPC Shop as a Customer for WooCommerce \u003c= 2.0.0 - Authenticated (Subscriber+) Privilege Escalation via Missing Role Check on Target User to wpcsa_login AJAX Endpoint"
}
},
"cveMetadata": {
"assignerOrgId": "b15e7b5b-3da4-40ae-a43c-f7aa60e62599",
"assignerShortName": "Wordfence",
"cveId": "CVE-2026-95687",
"datePublished": "2026-10-01T08:28:43.728Z",
"dateReserved": "2026-09-22T14:14:09.896Z",
"dateUpdated": "2026-10-01T08:28:43.728Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2024-12432 (GCVE-0-2024-12432)
Vulnerability from cvelistv5 – Published: 2024-12-18 03:22 – Updated: 2026-04-08 16:33
VLAI
EPSS
VEX
Title
WPC Shop as a Customer for WooCommerce <= 1.2.8 - Authentication Bypass Due to Insufficiently Unique Key
Summary
The WPC Shop as a Customer for WooCommerce plugin for WordPress is vulnerable to account takeover and privilege escalation in all versions up to, and including, 1.2.8. This is due to the 'generate_key' function not producing a sufficiently random value. This makes it possible for authenticated attackers, with Subscriber-level access and above, to log in as site administrators, granted they have triggered the ajax_login() function which generates a unique key that can be used to log in.
Severity
8.1 (High)
SSVC
Exploitation: none
Automatable: no
Technical Impact: total
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2024-12-18 16:25 UTC
CWE
- CWE-330 - Use of Insufficiently Random Values
Assigner
References
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| wpclever | WPC Shop as a Customer for WooCommerce |
Affected:
0 , ≤ 1.2.8
(semver)
|
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2024-12432",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2024-12-18T16:25:17.044195Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2024-12-18T16:35:53.912Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "WPC Shop as a Customer for WooCommerce",
"vendor": "wpclever",
"versions": [
{
"lessThanOrEqual": "1.2.8",
"status": "affected",
"version": "0",
"versionType": "semver"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "Thanh Nam Tran"
}
],
"descriptions": [
{
"lang": "en",
"value": "The WPC Shop as a Customer for WooCommerce plugin for WordPress is vulnerable to account takeover and privilege escalation in all versions up to, and including, 1.2.8. This is due to the \u0027generate_key\u0027 function not producing a sufficiently random value. This makes it possible for authenticated attackers, with Subscriber-level access and above, to log in as site administrators, granted they have triggered the ajax_login() function which generates a unique key that can be used to log in."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 8.1,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-330",
"description": "CWE-330 Use of Insufficiently Random Values",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-04-08T16:33:10.637Z",
"orgId": "b15e7b5b-3da4-40ae-a43c-f7aa60e62599",
"shortName": "Wordfence"
},
"references": [
{
"url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/048625e8-10b7-418d-a13b-329f1d7e0171?source=cve"
},
{
"url": "https://plugins.trac.wordpress.org/changeset?sfp_email=\u0026sfph_mail=\u0026reponame=\u0026old=3208130%40wpc-shop-as-customer\u0026new=3208130%40wpc-shop-as-customer\u0026sfp_email=\u0026sfph_mail="
}
],
"timeline": [
{
"lang": "en",
"time": "2024-12-17T00:00:00.000Z",
"value": "Disclosed"
}
],
"title": "WPC Shop as a Customer for WooCommerce \u003c= 1.2.8 - Authentication Bypass Due to Insufficiently Unique Key"
}
},
"cveMetadata": {
"assignerOrgId": "b15e7b5b-3da4-40ae-a43c-f7aa60e62599",
"assignerShortName": "Wordfence",
"cveId": "CVE-2024-12432",
"datePublished": "2024-12-18T03:22:00.850Z",
"dateReserved": "2024-12-10T17:11:11.238Z",
"dateUpdated": "2026-04-08T16:33:10.637Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2024-50416 (GCVE-0-2024-50416)
Vulnerability from cvelistv5 – Published: 2024-10-28 11:30 – Updated: 2026-05-12 22:59
VLAI
EPSS
VEX
Title
WordPress WPC Shop as a Customer for WooCommerce plugin <= 1.2.6 - PHP Object Injection vulnerability
Summary
Deserialization of Untrusted Data vulnerability in WPClever WPC Shop as a Customer for WooCommerce wpc-shop-as-customer allows Object Injection.This issue affects WPC Shop as a Customer for WooCommerce: from n/a through <= 1.2.6.
Severity
8.8 (High)
SSVC
Exploitation: poc
Automatable: no
Technical Impact: total
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2024-10-28 12:00 UTC
CWE
- CWE-502 - Deserialization of Untrusted Data
Assigner
References
1 reference
| URL | Tags |
|---|---|
| https://patchstack.com/database/Wordpress/Plugin/… | vdb-entry |
Impacted products
2 products
| Vendor | Product | Version | |
|---|---|---|---|
| WPClever | WPC Shop as a Customer for WooCommerce |
Affected:
0 , ≤ 1.2.6
(custom)
|
|
| wpclever | wpc_shop_as_a_customer_for_woocommerce |
Affected:
0 , ≤ 1.2.6
(custom)
cpe:2.3:a:wpclever:wpc_shop_as_a_customer_for_woocommerce:*:*:*:*:*:*:*:* |
Date Public
2026-04-01 16:28
{
"containers": {
"adp": [
{
"affected": [
{
"cpes": [
"cpe:2.3:a:wpclever:wpc_shop_as_a_customer_for_woocommerce:*:*:*:*:*:*:*:*"
],
"defaultStatus": "unknown",
"product": "wpc_shop_as_a_customer_for_woocommerce",
"vendor": "wpclever",
"versions": [
{
"lessThanOrEqual": "1.2.6",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
}
],
"metrics": [
{
"other": {
"content": {
"id": "CVE-2024-50416",
"options": [
{
"Exploitation": "poc"
},
{
"Automatable": "no"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2024-10-28T12:00:41.522329Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-05-12T22:59:46.855Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"collectionURL": "https://wordpress.org/plugins",
"defaultStatus": "unaffected",
"packageName": "wpc-shop-as-customer",
"product": "WPC Shop as a Customer for WooCommerce",
"vendor": "WPClever",
"versions": [
{
"changes": [
{
"at": "1.2.7",
"status": "unaffected"
}
],
"lessThanOrEqual": "1.2.6",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "LVT-tholv2k | Patchstack Bug Bounty Program"
}
],
"datePublic": "2026-04-01T16:28:48.086Z",
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "Deserialization of Untrusted Data vulnerability in WPClever WPC Shop as a Customer for WooCommerce wpc-shop-as-customer allows Object Injection.\u003cp\u003eThis issue affects WPC Shop as a Customer for WooCommerce: from n/a through \u003c= 1.2.6.\u003c/p\u003e"
}
],
"value": "Deserialization of Untrusted Data vulnerability in WPClever WPC Shop as a Customer for WooCommerce wpc-shop-as-customer allows Object Injection.This issue affects WPC Shop as a Customer for WooCommerce: from n/a through \u003c= 1.2.6."
}
],
"impacts": [
{
"capecId": "CAPEC-586",
"descriptions": [
{
"lang": "en",
"value": "Object Injection"
}
]
}
],
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 8.8,
"baseSeverity": "HIGH",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "LOW",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-502",
"description": "Deserialization of Untrusted Data",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-04-28T16:10:28.559Z",
"orgId": "21595511-bba5-4825-b968-b78d1f9984a3",
"shortName": "Patchstack"
},
"references": [
{
"tags": [
"vdb-entry"
],
"url": "https://patchstack.com/database/Wordpress/Plugin/wpc-shop-as-customer/vulnerability/wordpress-wpc-shop-as-a-customer-for-woocommerce-plugin-1-2-6-php-object-injection-vulnerability?_s_id=cve"
}
],
"title": "WordPress WPC Shop as a Customer for WooCommerce plugin \u003c= 1.2.6 - PHP Object Injection vulnerability"
}
},
"cveMetadata": {
"assignerOrgId": "21595511-bba5-4825-b968-b78d1f9984a3",
"assignerShortName": "Patchstack",
"cveId": "CVE-2024-50416",
"datePublished": "2024-10-28T11:30:58.130Z",
"dateReserved": "2024-10-24T07:25:21.566Z",
"dateUpdated": "2026-05-12T22:59:46.855Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}