PayU CommercePro Plugin Privilege Escalation Vulnerability in WordPress
Vulnerability
A privilege escalation vulnerability exists in the PayU CommercePro Plugin for WordPress, affecting all versions through 3.8.3. The vulnerability arises because the REST API endpoints '/wp-json/payu/v1/generate-user-token' and '/wp-json/payu/v1/get-shipping-cost' do not adequately verify user identity before assigning user IDs and authentication cookies. This flaw allows unauthenticated attackers to create new administrative accounts.
Impact
Exploitation of this vulnerability allows for unauthorized creation of administrative user accounts, potentially leading to further privilege escalation or unauthorized actions within the WordPress site.
Remediation
Users are advised to update the PayU CommercePro Plugin to version 3.8.4 or a newer patched version.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
