9.8

CVE-2025-6688

Simple Payment 1.3.6 - 2.3.8 - Authentication Bypass to Admin

Simple Payment 1.3.6 - 2.3.8 - Authentication Bypass to Admin

The Simple Payment plugin for WordPress is vulnerable to Authentication Bypass in versions 1.3.6 to 2.3.8. This is due to the plugin not properly verifying a user's identity prior to logging them in through the create_user() function. This makes it possible for unauthenticated attackers to log in as administrative users.
Mögliche Gegenmaßnahme
Simple Payment: Update to version 2.3.9, or a newer patched version
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
IdokdSimple Payment SwPlatformwordpress Version >= 1.3.6 < 2.3.9
Weitere Schwachstelleninformationen
SystemWordPress Plugin
Produkt Simple Payment
Version 1.3.6-2.3.8
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.45% 0.358
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
security@wordfence.com 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE-288 Authentication Bypass Using an Alternate Path or Channel

The product requires authentication, but the product has an alternate path or channel that does not require authentication.

https://www.wordfence.com/threat-intel/vulnerabilities/id/8b4e2f87-e3ad-4f1b-b647-f5e5a49f691b?source=cve
Third Party Advisory
https://plugins.trac.wordpress.org/changeset/3318371/simple-payment/tags/2.3.9/simple-payment-plugin.php
Patch
https://www.wordfence.com/threat-intel/vulnerabilities/id/8b4e2f87-e3ad-4f1b-b647-f5e5a49f691b
Third Party Advisory