CVE-2024-12402

CRITICAL

The Themes Coder – Create Android & iOS Apps For Your Woocommerce Site plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 1.3.4. T...

Affects 0 products across 5 vendors.

BCS7.12
CVSS 3.19.8
EPSS0.6%
Percentile45th
PatchUnknown
CVSS Vector — Plain English Remotely exploitable over the network, low complexity, no authentication required, no user interaction needed, impact contained to the vulnerable component, full confidentiality impact, full integrity impact, full availability impact.
CWE Weakness Definitions
CWE-288: CWE-288
Related Attack Patterns (CAPEC)
CAPEC-127 Directory Indexing
via CWE-288
CAPEC-665 Exploitation of Thunderbolt Protection Flaws
via CWE-288

Mapping is CWE-to-CAPEC per MITRE CAPEC 3.9.

◆ SAGE Intelligence — CITED Relevance Research Team

The Themes Coder – Create Android & iOS Apps For Your Woocommerce Site plugin for WordPress is vulnerable to privilege escalation via account takeover due to improper user identity validation in the update_user_profile() function.

BSID: BS-2025-GLOBAL-183435-C • Model: /workspace/models/qwen2.5-coder-32b-instruct-bf16 • Confidence: HIGH

Is this CVE in your environment?

BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.

Check My Environment →
Frequently Asked Questions
What is CVE-2024-12402?
The Themes Coder – Create Android & iOS Apps For Your Woocommerce Site plugin for WordPress is vulnerable to privilege escalation via account takeover due to improper user identity validation in the update_user_profile() function.
What is the CVSS score for CVE-2024-12402?
CVE-2024-12402 has CVSS 9.8 (Critical). Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. EPSS: 0.6%.
Is CVE-2024-12402 actively exploited?
No confirmed active exploitation of CVE-2024-12402 as of 2026-05-30.
How do I remediate CVE-2024-12402?
Priority: IMMEDIATE.
What systems are affected by CVE-2024-12402?
CVE-2024-12402 affects: Android, Coder, Plugin, Woocommerce, Wordpress.
Vulnerability Details
CVE IDCVE-2024-12402
BSIDBS-2025-GLOBAL-183435-C BreachSpider Global ID
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Published2025-01-07
Last Modified2026-04-15
ICS Relevance0%
Weakness (CWE)
SourceNVD
Official Description

The Themes Coder – Create Android & iOS Apps For Your Woocommerce Site plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 1.3.4. This is due to the plugin not properly validating a user's identity prior to updating their password through the update_user_profile() function. This makes it possible for unauthenticated attackers to change arbitrary user's passwords, including administrators, and leverage that to gain access to their account.

Source: NIST NVD / MITRE CVE Database

Attack Vector Analysis — CITED Relevance

Unauthenticated attackers can exploit this vulnerability to change a user's password, effectively taking over their account. This is possible because the plugin does not properly verify the user's identity before updating their password.

Exploitation Likelihood: CRITICAL

Affected Products
VendorProductFixed Version
Android —
Coder —
Plugin —
Woocommerce —
Wordpress —
Remediation

No patch URL on record. Monitor vendor security advisories directly.

Threat Intelligence
● Threat Intelligence Validated: July 2026 | Threat Age: 564 Days
CISA KEVNot in KEV catalog
Public ExploitNot confirmed
PoC CodeNot confirmed
SAGE Enrichment Record — provenance & audit hash
Model/workspace/models/qwen2.5-coder-32b-instruct-bf16
ConfidenceHIGH
Enriched At2026-05-24
SHA-512 Audit Hashac006aed7350884840b3010c73cbbc024ccbc52a82d7dc4b30ea334a68bc72173b0ba65591df1c2a548bfe3e42c2e00ac1aeb01b5e0f53e78e8a5c080f5ff145
Related CVEs affecting Android
CVE-2023-4617 10.0 Incorrect authorization vulnerability in HTTP POST method in Govee Home appli... CVE-2026-30496 9.8 The Optoma CinemaX P2 projector (firmware TVOS-04.24.010.04.01, Android 8.0.0... CVE-2024-53931 9.1 The com.glitter.caller.screen (aka iCaller, Caller Theme & Dialer) applicatio... CVE-2025-69515 9.1 An issue in JXL 9 Inch Car Android Double Din Player Android v12.0 allows att... CVE-2024-53932 9.1 The com.remi.colorphone.callscreen.calltheme.callerscreen (aka Color Phone: C...
View all Android CVEs →

Critical Severity - Know Your Exposure

A CVSS 9.8 vulnerability in your ICS environment cannot wait. BreachSpider maps critical CVEs to your specific assets and tells you what to fix first.

Check Your Assets Free →