
A patch has been released for a critical security flaw affecting the WooCommerce Payments plugin for WordPress, which is installed on over 500,000 websites.
In its March 23, 2023 advisory, leaving this flaw unresolved could allow malicious individuals to gain unauthorized administrative access to the affected store, the company said. says.
In other words, this issue could allow an “unauthenticated attacker to impersonate an administrator and take complete control of a website without requiring user interaction or social engineering.” says Wordfence, a WordPress security company.
The vulnerability appears to be in a PHP file named ‘class-platform-checkout-session.php’, said Sucuri researcher Ben Martin.
The vulnerability was discovered and reported by Michael Mazzolini of Swiss penetration testing firm GoldNetwork.
WooCommerce also said it worked with WordPress to automatically update the site with the affected version of the software. Patched versions include 4.8.2, 4.9.1, 5.0.4, 5.1.3, 5.2.2, 5.3.1, 5.4.1, 5.5.2, and 5.6.2.
Discover the hidden dangers of third-party SaaS apps
Are you aware of the risks associated with third-party app access to your company’s SaaS apps? Join our webinar to learn about the types of permissions granted and how to minimize the risks.
reserve a seat
Additionally, the e-commerce plugin’s administrators have said they are disabling the WooPay beta program due to concerns that security flaws could impact payment checkout services.
While there is no evidence that the vulnerability has been actively exploited to date, it is expected to be weaponized on a large scale once a proof of concept becomes available, said Wordfence researcher Ram Gall. warns Mr.
In addition to updating to the latest version, users are advised to check the newly added admin user. If so, change all admin passwords and rotate payment gateways and WooCommerce API keys.