Impact
The Shelf Planner plugin for WordPress contains a missing capability check on several REST API endpoints, allowing any unauthenticated user to alter critical settings such as ServerKey and LicenseKey, which can lead to unauthorized configuration changes and potential compromise of the plugin's integrity.
Affected Systems
Affected systems include all installations of the Shelf Planner Inventory Management for WooCommerce plugin up to and including version 2.8.1, regardless of the WordPress site or hosting environment.
Risk and Exploitability
The vulnerability has a CVSS score of 5.3 and an EPSS score of < 1%, indicating moderate severity and low exploitation probability; it is not included in the CISA KEV catalog. Attackers could exploit the flaw remotely via the plugin's REST API without authentication, making mitigation via updating the plugin the primary recommendation.
OpenCVE Enrichment