Executive brief
A vulnerability exists in a WordPress plugin used for managing product prices via a spreadsheet interface. This flaw allows unauthorized individuals to bypass security checks and create new administrator accounts on the website. An attacker could use this access to take full control of the site, steal customer data, or disrupt business operations. All versions up to and including 2.4.37 are affected.
Technical details
The Spreadsheet Price Changer for WooCommerce and WP E-commerce – Light plugin for WordPress suffers from a missing authorization vulnerability within the user_filter function located in the sellingcommander.php file. The root cause is a failure to implement proper permission checks on sensitive functionality, allowing unauthenticated remote attackers to trigger account creation logic. By sending a specially crafted request, an attacker can register a new user account with administrative privileges. This vulnerability affects all versions up to and including 2.4.37. Security teams should update to a patched version immediately or disable the plugin if no update is available.
Affected products
- holest Spreadsheet Price Changer for WooCommerce and WP E-commerce – Light 0 - 2.4.37
Timeline
- 2026-07-29: disclosed: Initial disclosure by Wordfence
- 2026-07-29: advisory: NVD publication date