EasyCommerce WordPress Plugin Privilege Escalation Vulnerability
Vulnerability
A privilege escalation vulnerability has been identified in the EasyCommerce WordPress eCommerce plugin, specifically in versions 0.9.0-beta2 through 1.5.0. The issue arises from the /easycommerce/v1/orders REST API endpoint, which fails to properly restrict user role selection during registration. This flaw allows unauthenticated attackers to gain administrator-level access on vulnerable WordPress sites.
Impact
Exploitation of this vulnerability allows unauthenticated users to gain administrative privileges on the affected WordPress site.
Remediation
No known patch is available. Users are advised to review the vulnerability details and consider uninstalling the affected plugin.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
