WordPress Simpler Checkout Plugin Authentication Bypass Vulnerability

Vulnerability

A vulnerability allowing authentication bypass has been identified in the Simpler Checkout plugin for WordPress, affecting versions 0.7.0 to 1.1.9. The issue arises because the plugin fails to properly verify a user's identity before logging them in as an administrator via the 'simplerwc_woocommerce_order_created()' function. This flaw enables unauthenticated attackers to log in as other users by exploiting their order ID, potentially gaining access as an administrator if a test order was placed by a site admin.

Impact

Exploitation of this vulnerability allows unauthenticated users to log in as other users, including administrators, by using their order ID.

Remediation

There is no known patch available for this vulnerability. It is recommended to review the vulnerability details and consider uninstalling the affected plugin.

Added: Aug 23, 2025, 5:23 AM
Updated: Aug 23, 2025, 5:23 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
5.0
exploitability
8.1
remediation
0.0
relevance
0.4
threat
3.2
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.