WordPress Plugin Vulnerabilities
Hippoo Mobile App for WooCommerce < 1.9.5 - Unauthenticated Authentication Bypass to Administrator Account Takeover via REST API
Description
The plugin is vulnerable to an authentication bypass leading to administrator account takeover due to a logic conflation in `HippooPermissions::get_user_permissions()`, which returns the same null sentinel for both administrators and unauthenticated visitors — a value that `HippooPermissions::has_role_access()` unconditionally interprets as full administrator access. This causes `override_extension_permission_callback()` to assign `__return_true` as the permission callback for every WordPress and WooCommerce REST route cloned under `/wc-hippoo/v1/ext/` by `HippooControllerWithAuth::re_register_external_routes()`, while the `block_unauthorized_access()` pre-dispatch guard fails to block unauthenticated users for the same reason. This makes it possible for unauthenticated attackers to invoke any core REST endpoint without credentials — most critically, sending a POST request to `/wc-hippoo/v1/ext/wp/v2/users/<id>` with a `{"password":"<new_password>"}` body to reset the password of any user, including the site administrator, and gain full administrative control of the site.