Impact
Missing Authorization vulnerability in WPFactory EAN for WooCommerce allows attackers to exploit incorrectly configured access control security levels. The weakness enables an actor to invoke protected functions without meeting the required permissions, thereby granting unauthorized access to the EAN barcode generation capability. This compromise can lead to unauthorized creation or disclosure of barcode data, potentially undermining inventory integrity or exposing sensitive product information.
Affected Systems
WordPress plugin "EAN for WooCommerce" by WPFactory, affected from the earliest available release through version 5.3.5. Any site running one of these versions and having the plugin installed is vulnerable.
Risk and Exploitability
The CVSS score of 4.3 indicates a moderate severity, while the EPSS score of less than 1% suggests a low likelihood of widespread exploitation at present. The vulnerability is not listed in CISA’s Known Exploited Vulnerabilities catalog. The likely attack vector is an authenticated user with insufficient role checks, inferred from the description of access control misconfiguration. No additional exploitation prerequisites are documented in the CVE data.
OpenCVE Enrichment
EUVD