CVE-2024-12259: SWEETDAISY86 Repairbuddy – Repair Shop CRM & Booking Plugin For WordPress

High severity, CVSS 8.8. EPSS: 0.5% chance of exploitation in the next 30 days.

The CRM WordPress Plugin – RepairBuddy plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 3.8120. This is due to the plugin not properly validating a user's identity prior to updating their email through the wc_update_user_data AJAX action. This makes it possible for authenticated attackers, with subscriber-level access and above, to change arbitrary user's email addresses, including administrators, and leverage that to reset the user's password and gain access to their account.

Affected products

  • SWEETDAISY86 Repairbuddy – Repair Shop CRM & Booking Plugin For WordPress: up to and including 3.8120

Published 2024-12-18. Last modified 2026-06-17.