WordPress Plugin Vulnerabilities
Biometric Login for WooCommerce < 1.0.4 - Unauthenticated Privilege Escalation
Description
The plugin does not validate that a user's WebAuthn authentication request succeeded before sending them authentication cookies, making it possible for unauthenticated attackers to take over any accounts having WebAuthn credentials set up on affected sites.
Proof of Concept
Affects Plugins
Classification
Type
PRIVESC
OWASP top 10
CWE
CVSS
Miscellaneous
Original Researcher
Alexander Concha
Verified
Yes
WPVDB ID
Timeline
Publicly Published
2023-08-08 (about 2 years ago)
Added
2023-08-08 (about 2 years ago)
Last Updated
2023-08-08 (about 2 years ago)