CVE-2025-7642 | Teknoloji dünyasından en güncel haberleri ve güvenlikle ilgili gelişmeleri takip edin.

The Simpler Checkout plugin for WordPress is vulnerable to Authentication Bypass in versions 0.7.0 to 1.1.9. This is due to the plugin not properly verifying a…
Critical CVSS: 9.8

CVE-2025-7642

The Simpler Checkout plugin for WordPress is vulnerable to Authentication Bypass in versions 0.7.0 to 1.1.9. This is due to the plugin not properly verifying a user's identity prior to logging them in as an admin through the simplerwc_woocommerce_order_created() function. This makes it possible for unauthenticated attackers to log in as other users based on their order ID, which can be an administrator if a site admin has placed a test order.
Vendor
-
Product
-
CWE
CWE-288
Yayın Tarihi
2025-08-23 05:15:32
Güncelleme
2025-08-25 20:24:45
Source Identifier
security@wordfence.com
KEV Date Added
-

Kategoriler

Referanslar