Impact
The Premmerce Brands for WooCommerce plugin contains a missing capability check in its saveBrandsSettings function. This flaw allows authenticated users with Subscriber-level access or higher to modify brand permalink settings without authorization. As a result, those users can change URLs, potentially disrupting branding, redirecting traffic, or facilitating malicious content targeting visitors. The flaw is a typical example of a missing authorization check (CWE‑862).
Affected Systems
The vulnerability affects the Premmerce Brands for WooCommerce WordPress plugin. All releases up to and including version 1.2.13 are impacted. Users of any WordPress installation running these versions are at risk.
Risk and Exploitability
The CVSS score of 4.3 indicates moderate severity, and the EPSS score of less than 1% suggests exploitation is unlikely at the time. The flaw is not in the CISA KEV catalog. Attackers would need to be authenticated with at least Subscriber privileges; a privilege escalation or compromised account would provide the necessary access.
OpenCVE Enrichment