Description
Missing Authorization vulnerability in aribhour Linet ERP-Woocommerce Integration linet-erp-woocommerce-integration allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Linet ERP-Woocommerce Integration: from n/a through <= 3.5.7.
Published: 2025-01-24
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability arises from missing authorization checks in the Linet ERP-Woocommerce Integration plugin. Incorrectly configured access control enables an attacker to perform actions beyond the intended privilege level, potentially creating or modifying ERP data and disrupting business processes. The weakness is classified as CWE-862.

Affected Systems

WordPress sites running aribhour’s Linet ERP-Woocommerce Integration plugin version 3.5.7 or earlier are vulnerable. The plugin synchronizes ERP information with WooCommerce, and any user with access to these plugin endpoints can exploit the flaw.

Risk and Exploitability

The CVSS score of 6.5 denotes moderate severity, while an EPSS score of less than 1 % indicates a low likelihood of exploitation. The vulnerability is not included in the CISA KEV catalog and no public exploit has been documented. Attackers likely require a CSRF scenario or direct exploitation of missing authorization during authenticated sessions. Prompt patching is advised to mitigate potential risk.

Generated by OpenCVE AI on May 1, 2026 at 18:52 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Linet ERP-Woocommerce Integration plugin to version 3.5.8 or later.
  • Limit the plugin’s usage to administrators by reviewing and restricting role capabilities.
  • Configure a web application firewall to block unauthorized endpoints and HTTP methods related to the plugin.

Generated by OpenCVE AI on May 1, 2026 at 18:52 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-3798 Missing Authorization vulnerability in Speedcomp Linet ERP-Woocommerce Integration allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Linet ERP-Woocommerce Integration: from n/a through 3.5.7.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Missing Authorization vulnerability in Speedcomp Linet ERP-Woocommerce Integration allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Linet ERP-Woocommerce Integration: from n/a through 3.5.7. Missing Authorization vulnerability in aribhour Linet ERP-Woocommerce Integration linet-erp-woocommerce-integration allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Linet ERP-Woocommerce Integration: from n/a through <= 3.5.7.
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L'}


Fri, 24 Jan 2025 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 24 Jan 2025 17:30:00 +0000

Type Values Removed Values Added
Description Missing Authorization vulnerability in Speedcomp Linet ERP-Woocommerce Integration allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Linet ERP-Woocommerce Integration: from n/a through 3.5.7.
Title WordPress Linet ERP-Woocommerce Integration plugin <= 3.5.7 - CSRF to Broken Access Control vulnerability
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-05-12T23:49:52.519Z

Reserved: 2025-01-23T14:50:57.838Z

Link: CVE-2025-24594

cve-icon Vulnrichment

Updated: 2025-01-24T18:47:25.620Z

cve-icon NVD

Status : Deferred

Published: 2025-01-24T18:15:36.330

Modified: 2026-06-17T08:59:17.233

Link: CVE-2025-24594

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-01T19:00:08Z

Weaknesses