Back

CRITICAL

Booster for WooCommerce <= 5.4.3 Authentication Bypass

Published Aug 30, 2021

Description

Versions up to, and including, 5.4.3, of the Booster for WooCommerce WordPress plugin are vulnerable to authentication bypass via the process_email_verification function due to a random token generation weakness in the reset_and_mail_activation_link function found in the ~/includes/class-wcj-emails-verification.php file. This allows attackers to impersonate users and trigger an email address verification for arbitrary accounts, including administrative accounts, and automatically be logged in as that user, including any site administrators. This requires the Email Verification module to be active in the plugin and the Login User After Successful Verification setting to be enabled, which it is by default.

Affected products

Remediation

Vendor solution

Update to version 5.4.4 or newer.

References (3)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner Wordfence
Published Aug 30, 2021
Updated May 5, 2025
Reserved Jun 10, 2021
CISA Vulnrichment
Updated May 5, 2025
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a
ENISA EUVD
Assigner Wordfence
Published Aug 30, 2021
Updated May 5, 2025
Exploited since n/a
EUVD-2021-21296