WordPress.WooCommerce.Authentication.Bypass

description-logoDescription

This indicates an attack attempt to exploit an Authentication Bypass vulnerability in WordPress plugin WooCommerce.
The vulnerability is due to the application's failure to properly check user input while handling a craft HTTP request. A remote unauthenticated attacker could exploit this vulnerability by sending an HTTP request to the target server. Successfully exploiting these vulnerabilities could allow an attacker to log in as an authenticated user.

description-logoOutbreak Alert

An authentication bypass vulnerability affecting the WooCommerce Payments plugin version 4.8.0 through 5.6.1. Successful exploitation of the vulnerability could allow an unauthorized attacker to gain admin privileges on the WordPress websites potentially leading to the site takeover, impersonate arbitrary users, including an administrator.

View the full Outbreak Alert Report

affected-products-logoAffected Products

WordPress WooCommerce Plugin <= 5.6.1

Impact logoImpact

Security Bypass: Remote attackers can bypass security features of vulnerable systems.

Telemetry logoTelemetry

Coverage

IPS (Regular DB)
IPS (Extended DB)

Version Updates

Date Version Detail
2023-07-27 25.610 Default_action:pass:drop
2023-07-24 25.607