CVE-2024-13513

CRITICAL

Oliver POS <= 2.4.2.3 - Unauthenticated Sensitive Information Exposure via Logging

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 2 public exploits for CVE-2024-13513. PoCs published by 0axz-tools, KTN1990.

AI-analyzed exploit summary This repository contains a functional exploit for CVE-2024-13513, targeting the Oliver POS WordPress plugin. The exploit scans for vulnerable installations, extracts client tokens from log files, and performs an unauthorized email change for the admin user via a crafted HTTP request.

Description

The Oliver POS – A WooCommerce Point of Sale (POS) plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.4.2.3 via the logging functionality. This makes it possible for unauthenticated attackers to extract sensitive data including the plugin's clientToken, which in turn can be used to change user account information including emails and account type. This allows attackers to then change account passwords resulting in a complete site takeover. Version 2.4.2.3 disabled logging but left sites with existing log files vulnerable.

Exploits (2)

nomisec WORKING POC
by 0axz-tools · poc
https://github.com/0axz-tools/CVE-2024-13513.py

This repository contains a functional exploit for CVE-2024-13513, targeting the Oliver POS WordPress plugin. The exploit scans for vulnerable installations, extracts client tokens from log files, and performs an unauthorized email change for the admin user via a crafted HTTP request.

Classification
Working Poc 95%
Attack Type
Auth Bypass
Complexity
Moderate
Reliability
Reliable
Target: Oliver POS WordPress plugin (versions before 2.4.2.4)
No auth needed
Prerequisites: Target must have the vulnerable Oliver POS plugin installed · Log files must be accessible at /wp-content/plugins/oliver-pos/log/
devstral-2 · analyzed Feb 19, 2026 Full analysis →
nomisec WORKING POC
by KTN1990 · poc
https://github.com/KTN1990/CVE-2024-13513

The repository contains a functional Python exploit for CVE-2024-13513, targeting the Oliver POS WooCommerce plugin. It extracts sensitive client tokens from log files and uses them to change user account information, leading to privilege escalation and site takeover.

Classification
Working Poc 95%
Attack Type
Info Leak | Auth Bypass
Complexity
Moderate
Reliability
Reliable
Target: Oliver POS – A WooCommerce Point of Sale (POS) plugin for WordPress <= 2.4.2.3
No auth needed
Prerequisites: Access to the target WordPress site · Exposed log files containing clientToken
devstral-2 · analyzed Feb 18, 2026 Full analysis →

Scores

CVSS v3 9.8
EPSS 0.0072
EPSS Percentile 49.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

CWE
CWE-862
Status published
Products (2)
oliverpos/Oliver POS – A WooCommerce Point of Sale (POS) < 2.4.2.3
oliverpos/oliver_pos < 2.4.2.4
Published Feb 15, 2025
Tracked Since Feb 18, 2026