WPClever WPC Smart Linked Products Privilege Escalation Vulnerability
Vulnerability
A missing authorization vulnerability in the WPClever WPC Smart Linked Products - Upsells & Cross-sells for WooCommerce plugin, affecting versions through 1.3.5, allows for privilege escalation. This vulnerability could enable a low-privileged user to gain higher privileges, potentially leading to full control of the website.
Impact
Exploitation of this vulnerability could allow a low-privileged user to escalate their privileges, gaining higher access rights and possibly full control over the website.
Remediation
Users of the WPC Smart Linked Products - Upsells & Cross-sells for WooCommerce plugin should update to version 1.3.6 or later. Patchstack users can enable auto-updates for vulnerable plugins.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
