Impact
The vulnerability arises from missing authorization in the TicketBAI Facturas para WooCommerce plugin, allowing an attacker to exploit incorrectly configured access control security levels and potentially read or modify invoice data that should be restricted. The flaw is a classic example of CWE‑862, a missing authorization issue.
Affected Systems
The affected product is FacturaOne’s TicketBAI Facturas para WooCommerce plugin. Any installation of the plugin running a version up to and including 3.45 is vulnerable. No specific sub‑version constraints are listed.
Risk and Exploitability
The CVSS score of 5.4 indicates moderate severity, while the EPSS score of less than 1% shows a low probability of exploitation. The vulnerability is not in the CISA KEV catalog. Based on the description, it is inferred that attackers would likely target exposed administrative endpoint URLs that do not perform proper role checks; without correct authorization layers, a malicious actor could gain read or write access to invoice information and possibly move laterally within the site if multiple user roles are compromised.
OpenCVE Enrichment
EUVD