vendor:
Booster for WooCommerce
by:
Sebastian Kriesten (0xB455)
9,8
CVSS
CRITICAL
Authentication Bypass
287
CWE
Product Name: Booster for WooCommerce
Affected Version From: <= 5.4.3
Affected Version To: >= 5.4.4
Patch Exists: YES
Related CWE: CVE-2021-34646
CPE: a:booster_for_woocommerce:booster_for_woocommerce
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: None
2021
WordPress Plugin WooCommerce Booster Plugin 5.4.3 – Authentication Bypass
An authentication bypass vulnerability was patched in Booster for WooCommerce plugin. Attackers can exploit this vulnerability by visiting the target website's wp-json/wp/v2/users/ page, picking a user-ID, and then using the exploit_CVE-2021-34646.py script to generate multiple timestamps in order to avoid delay related timing errors. One of the generated links will allow the attacker to access the system.
Mitigation:
Update to the latest version of the Booster for WooCommerce plugin.