Impact
The Product Size Charts Plugin for WooCommerce contains a missing authorization flaw that permits unauthorized users to access or modify product size chart data. Attackers could retrieve sensitive configuration or alteration information, potentially impacting inventory visibility and pricing accuracy. This weakness is classified as CWE‑862 Broken Access Control.
Affected Systems
The vulnerability is present in Dotstore’s Product Size Charts Plugin for WooCommerce versions up to and including 2.4.5. WordPress sites running these versions with WooCommerce will be affected.
Risk and Exploitability
The CVSS score is 4.3, indicating moderate risk. EPSS is less than 1 %, implying a low probability of current exploitation. The plugin is not listed in the CISA KEV catalog. The likely attack vector is a web‑based interaction with the plugin’s administrative interface or REST endpoints that do not enforce proper access checks.
OpenCVE Enrichment
EUVD