Impact
The Spreadsheet Price Changer for WooCommerce and WP E-commerce – Light plugin suffers from a missing authorization check in its user_filter function. This flaw lets any unauthenticated user craft a request that creates a new administrator account, giving the attacker full control over the WordPress site. The impact spans confidentiality, integrity, and availability because a newly created admin can change settings, add malicious plugins, or exfiltrate data.
Affected Systems
The vulnerability affects the WordPress plugin Spreadsheet Price Changer for WooCommerce and WP E-commerce – Light from vendor holest, specifically all releases up to and including version 2.4.37. Users running these versions on any WordPress installation are exposed, regardless of other security measures.
Risk and Exploitability
With a CVSS score of 9.8, this is a critical flaw. The EPSS score indicates a very low current exploitation probability, yet the lack of authentication requirements makes exploitation straightforward once an attacker discovers the vulnerable endpoint. The flaw is not listed in the CISA KEV catalog but could quickly become widely abused if the plugin remains unpatched. The likely attack path involves sending a specially crafted HTTP request to the plugin’s admin endpoint, bypassing all authorization checks and creating a privileged account.
OpenCVE Enrichment