Web Hack List

Later archive addition

WordPress Design Flaw Leads to WooCommerce RCE

The article shows how a WordPress capability-design flaw could let a compromised WooCommerce shop-manager account alter settings outside its intended scope. The attacker can gain administrative control and then use standard plugin or theme functionality to execute code on the server.

Record

Researcher
Simon Scannell
Published by
Sonar
Date

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of Simon Scannell, first published at the original source. Preserved copies are kept so the citation survives its host.