Impact
The vulnerability is a missing authorization flaw (CWE-862) in the Build Private Store For Woocommerce plugin. The plugin fails to enforce proper access checks on its administrative interfaces, allowing an attacker to access or modify private store settings that should be restricted to privileged WordPress users. This could enable unauthorized viewing or alteration of private storefront content, inventory management, or order processing functions, compromising the confidentiality and integrity of store data.
Affected Systems
The affected product is Build Private Store For Woocommerce from SilverPlugins217. All released versions from the initial release up through version 1.0 are affected, meaning that any installation running version 1.0 or earlier is at risk.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate potential impact, and the EPSS score of less than 1% suggests a very low likelihood of exploitation in the wild. This vulnerability is not currently listed in the CISA KEV catalog. Based on the description, the attack vector would be remote via the WordPress web interface, where an attacker could send crafted requests to the plugin's admin endpoints to bypass normal capability checks.
OpenCVE Enrichment
EUVD