Holest Engineering Spreadsheet Price Changer for WooCommerce and WP E-commerce – Light Privilege Escalation Vulnerability
Vulnerability
A privilege escalation vulnerability has been identified in the Holest Engineering Spreadsheet Price Changer for WooCommerce and WP E-commerce – Light plugin, affecting versions through 2.4.37. This vulnerability allows unauthorized users to gain elevated privileges, potentially leading to full control over the website.
Impact
Exploitation of this vulnerability could allow a low-privileged user to escalate their privileges, gaining higher access rights and possibly full control over the website.
Remediation
Users are advised to update to a version of the Spreadsheet Price Changer for WooCommerce and WP E-commerce – Light plugin that is later than 2.4.37. For those using Patchstack, a virtual patch is available to mitigate this vulnerability until an official fix can be applied.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
