Impact
The vulnerability is a missing authorization check in the Woo Product Feed For Marketing Channels plugin, classified as CWE‑862. It permits a user who has not been granted explicit permission to call privileged functions or view configuration pages that should be restricted. The effect is that an attacker could read or modify feed settings, potentially affecting product visibility or data integrity.
Affected Systems
The issue affects all releases of the Woo Product Feed For Marketing Channels plugin up to and including version 1.9.0, distributed by Asaquzzaman Mishu for WordPress.
Risk and Exploitability
The CVSS score of 7.5 indicates high severity, while the EPSS score of less than 1 % suggests low likelihood of current exploitation. The vulnerability is not listed in the CISA KEV catalog. Attackers would need access to the plugin’s administrative interface, which typically requires a registered WordPress user. The missing authorization check is inferred from the description, meaning an attacker who can reach those endpoints—whether authenticated or not—could exercise functions beyond their intended privilege level.
OpenCVE Enrichment
EUVD