Impact
The vulnerability arises from missing authorization checks in the Linet ERP-Woocommerce Integration plugin. Incorrectly configured access control enables an attacker to perform actions beyond the intended privilege level, potentially creating or modifying ERP data and disrupting business processes. The weakness is classified as CWE-862.
Affected Systems
WordPress sites running aribhour’s Linet ERP-Woocommerce Integration plugin version 3.5.7 or earlier are vulnerable. The plugin synchronizes ERP information with WooCommerce, and any user with access to these plugin endpoints can exploit the flaw.
Risk and Exploitability
The CVSS score of 6.5 denotes moderate severity, while an EPSS score of less than 1 % indicates a low likelihood of exploitation. The vulnerability is not included in the CISA KEV catalog and no public exploit has been documented. Attackers likely require a CSRF scenario or direct exploitation of missing authorization during authenticated sessions. Prompt patching is advised to mitigate potential risk.
OpenCVE Enrichment
EUVD