Impact
The Search, Filters & Merchandising for WooCommerce plugin contains a missing capability check on the "wcis_save_email" endpoint, allowing attackers who are Authenticated with Subscriber-level access or higher to deactivate the plugin. This capability misconfiguration gives the attacker the ability to remove the plugin from an active WordPress site, leading to loss of functionality and potential disruption of e‑commerce operations.
Affected Systems
The vulnerability is present in all releases of the Search, Filters & Merchandising for WooCommerce plugin up to and including version 3.0.67. Systems running any of these versions on WordPress are susceptible if an attacker can authenticate with a Subscriber or higher role.
Risk and Exploitability
The CVSS score of 4.3 indicates a moderate severity with limited impact. An EPSS score of less than 1% suggests a very low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. Attackers must first authenticate on the site with Subscriber-level privileges to exploit the flaw, making it an authenticated, internal attack vector with potential for denial of service by disabling the plugin.
OpenCVE Enrichment