Critical WordPress plugin bug puts thousands of sites in danger

An abstract image of padlocks overlaying a digital background.
(Image credit: Shutterstock)

An authentication bypass vulnerability in a popular WordPress plugin enables attackers to take complete control over WordPress-powered ecommerce websites, researchers have revealed.

The Wordfence Threat Intelligence team discovered the vulnerability in the Booster for WooCommerce WordPress plugin, which boasts a user base of over 100,000 websites.

The Booster plugin offers over 100 features available in the WooCommerce plugin that helps setup ecommerce stores on WordPress installations

“This flaw made it possible for an attacker to log in as any user, as long as certain options were enabled in the plugin,” writes Wordfence's Chloe Chamberland.

Forging identities

With a CVSS score of 9.8, Chamberland explains that the vulnerability existed in the plugin’s Email Verification module. The module requires users to verify their email after they have registered on the site. 

However, the module didn’t perform the necessary security checks, making it possible for attackers to send a fake verification request as any user and essentially be able to log in with the forged identity.

“As such, an attacker could exploit this vulnerability to gain administrative access on sites running a vulnerable version of the plugin and effectively take-over the site,” explains Chamberland.

A patched version of the plugin has already been released, and Wordfence urges users of the plugin to upgrade to the latest release without delay.   

TOPICS
Mayank Sharma

With almost two decades of writing and reporting on Linux, Mayank Sharma would like everyone to think he’s TechRadar Pro’s expert on the topic. Of course, he’s just as interested in other computing topics, particularly cybersecurity, cloud, containers, and coding.

Read more
WordPress
WordPress users beware - these popular theme plugins have some major security issues
Laptop computer displaying logo of WordPress, a free and open-source content management system (CMS)
Another serious WordPress plugin vulnerability could put 40,000 sites at risk of attack
Laptop computer displaying logo of WordPress, a free and open-source content management system (CMS)
Over a million WordPress sites exposed to attack from W3 Total Cache plugin flaw
WordPress
Another top WordPress plugin found carrying critical security flaws
Laptop computer displaying logo of WordPress, a free and open-source content management system (CMS)
This top WordPress plugin could be hiding a worrying security flaw, so be on your guard
Laptop computer displaying logo of WordPress, a free and open-source content management system (CMS)
Thousands of WordPress websites hit in new malware attack, here's what we know
Latest in Website Building
Wix automation
The world's leading website builder aims to save businesses time with new tool
Squarespace
Build a website for less with 10% off Squarespace subscriptions
Squarespace
Fresh season, fresh start— launch your dream website with Squarespace with this offer
Wix Printful
Wix teams up with Printful for in-house print-on-demand tools
Squarespace
Don't miss out on this great Squarespace deal
Hostinger Website Builder vs WordPress.com: Which is better?
Hostinger Website Builder vs WordPress.com: Battle of the WordPress website builders
Latest in News
Open AI
OpenAI unveiled image generation for 4o – here's everything you need to know about the ChatGPT upgrade
Apple WWDC 2025 announced
Apple just announced WWDC 2025 starts on June 9, and we'll all be watching the opening event
Hornet swings their weapon in mid air
Hollow Knight: Silksong gets new Steam metadata changes, convincing everyone and their mother that the game is finally releasing this year
OpenAI logo
OpenAI just launched a free ChatGPT bible that will help you master the AI chatbot and Sora
An aerial view of an Instavolt Superhub for charging electric vehicles
Forget gas stations – EV charging Superhubs are using solar power to solve the most annoying thing about electric motoring
NetSuite EVP Evan Goldberg at SuiteConnect London 2025
"It's our job to deliver constant innovation” - NetSuite head on why it wants to be the operating system for your whole business