The SMS Alert Order Notifications – WooCommerce plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 3.7.9. This is due to the plugin using the Host header to determine if the plugin is in a playground environment. This makes it possible for unauthenticated attackers to spoof the Host header to make the OTP code "1234" and authenticate as any user, including administrators.
Metrics
Affected Vendors & Products
References
History
Tue, 01 Apr 2025 14:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Tue, 01 Apr 2025 11:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | The SMS Alert Order Notifications – WooCommerce plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 3.7.9. This is due to the plugin using the Host header to determine if the plugin is in a playground environment. This makes it possible for unauthenticated attackers to spoof the Host header to make the OTP code "1234" and authenticate as any user, including administrators. | |
Title | SMS Alert Order Notifications – WooCommerce <= 3.7.9 - Unauthenticated Account Takeover/Privilege Escalation | |
Weaknesses | CWE-288 | |
References |
|
|
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2025-04-01T13:57:05.060Z
Reserved: 2025-01-20T20:38:30.320Z
Link: CVE-2024-13553

Updated: 2025-04-01T13:57:00.492Z

Status : Awaiting Analysis
Published: 2025-04-01T12:15:14.643
Modified: 2025-04-01T20:26:11.547
Link: CVE-2024-13553

No data.