Impact
The Hide Categories Or Products On Shop Page plugin for WordPress is vulnerable to Cross‑Site Request Forgery (CWE‑352) caused by missing or incorrect nonce validation in its save_data_hcps() function. This flaw allows an unauthenticated attacker to force an administrator or other privileged user to submit a forged request that updates the plugin’s settings. The resulting configuration changes can hide categories or products on the shop page, potentially altering site functionality, degrading user experience, or creating a denial of service scenario for legitimate users.
Affected Systems
The vulnerability affects the WordPress plugin Hide Categories Or Products On Shop Page developed by Kaushik Ankrani. All installed copies running version 1.0.7 or earlier are susceptible. The impact is confined to sites that have the plugin active and rely on its settings to control product visibility.
Risk and Exploitability
With a CVSS score of 4.3, the flaw represents moderate severity. Its EPSS score is below 1 %, indicating a low probability of exploitation in the general population. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is a social‑engineering scenario where an attacker sends a malicious link to a site administrator, who, without realizing it, performs a state‑changing request that the plugin accepts without valid nonce verification. No additional technical requirements beyond tricking a privileged user are needed for exploitation.
OpenCVE Enrichment