module

Wordpress Plugin WooCommerce Payments Unauthenticated Admin Creation

Disclosed
2023-03-22
Created
2023-07-11

Description

WooCommerce-Payments plugin for Wordpress versions 4.8', '4.8.2, 4.9', '4.9.1,
5.0', '5.0.4, 5.1', '5.1.3, 5.2', '5.2.2, 5.3', '5.3.1, 5.4', '5.4.1,
5.5', '5.5.2, and 5.6', '5.6.2 contain an authentication bypass by specifying a valid user ID number
within the X-WCPAY-PLATFORM-CHECKOUT-USER header. With this authentication bypass, a user can then use the API
to create a new user with administrative privileges on the target WordPress site IF the user ID
selected corresponds to an administrator account.

Authors

h00die
Michael Mazzolini
Julien Ahrens

Module Options

To display the available options, load the module within the Metasploit console and run the commands ‘show options’ or ‘show advanced’:


msf > use auxiliary/scanner/http/wp_woocommerce_payments_add_user
msf auxiliary(wp_woocommerce_payments_add_user) > show actions
...actions...
msf auxiliary(wp_woocommerce_payments_add_user) > set ACTION < action-name >
msf auxiliary(wp_woocommerce_payments_add_user) > show options
...show and set options...
msf auxiliary(wp_woocommerce_payments_add_user) > run

Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.