Horizon Alert
Summary of the vulnerability and why it matters
A critical vulnerability has been identified in a WordPress plugin used for managing product pricing in WooCommerce and WP E-commerce stores. This issue allows unauthenticated attackers to create new administrator accounts, potentially leading to unauthorized access and control of affected websites. The main concern is confirming relevance and exposure of this plugin within your digital assets.
- Unauthenticated attackers can create admin accounts.
- Confirms plugin's presence and potential exposure.
- Assess and confirm relevance to your business.
Attack Path
How an attacker could exploit the issue
An unauthenticated attacker can exploit this vulnerability by sending a crafted request to a vulnerable WordPress site. This request targets a specific function within the Spreadsheet Price Changer plugin, which fails to properly check user authorization. Successful exploitation allows an attacker to create a new administrator account, giving them full control over the WordPress site.
- No authentication required.
- Triggered via a specific function call.
- Allows creation of admin accounts.
Live Threat
Current exploitation, exposure, and threat context
This vulnerability could allow unauthenticated attackers to create new administrative accounts on a WordPress site that uses the affected plugin. This access could potentially impact the integrity and availability of the website's services and data.
- Website administrative access at risk.
- Unauthenticated users could create accounts.
- Compromised website integrity and availability.
Operational Fix
Recommended remediation, mitigation, and detection steps
The WordPress plugin "Spreadsheet Price Changer for WooCommerce and WP E-commerce – Light" is susceptible to critical vulnerabilities that could allow unauthenticated attackers to create administrative accounts. Responsibility for addressing this likely falls to the team managing the WordPress application and its plugins, often the application owners or a dedicated web platform team. The first practical step is to confirm the presence and reachability of this plugin across your WordPress instances, identify the accountable owner for each, and then prioritize remediation based on business criticality and exposure.
- Application owners should own the issue.
- Verify plugin reachability and business criticality.
- Plan remediation based on identified risk.