Impact
The Pure WC Variation Swatches plugin for WordPress through version 1.1.7 does not perform an authentication check when updating its configuration. Because of this, any user who can log into the WordPress site can modify the plugin’s settings. These changes can alter the site’s appearance or behavior, potentially causing undesired effects.
Affected Systems
The vulnerability affects the Pure WC Variation Swatches plugin for WordPress with version numbers up to and including 1.1.7. Versions 1.1.8 and later are presumed to contain the fix. Site administrators should verify the installed version before proceeding.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity, while the EPSS score of less than 1% suggests a low likelihood of exploitation at present. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires only user authentication, and can be achieved via the plugin’s settings interface, making the attack vector accessible to any authenticated user, including those with limited roles.
OpenCVE Enrichment