Impact
The vulnerability is a missing authorization flaw that allows users to access plugin functionality that is not properly restricted by access control lists. This broken access control can enable an attacker to perform actions or view data that they should not be able to, potentially compromising confidentiality, integrity, or availability of the e‑commerce site.
Affected Systems
The issue affects the Ni WooCommerce Product Enquiry plugin developed by Anzar Ahmed. All released versions up to and including 4.1.8 are vulnerable, as indicated by the affected‑product range "from n/a through <= 4.1.8".
Risk and Exploitability
The CVSS score of 7.5 classifies the vulnerability as high severity. The EPSS score is less than 1%, suggesting a low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. Although the specific exploitation path is not detailed in the description, the likely attack vector involves web-based requests to the plugin’s endpoints, potentially by any authenticated or unauthenticated user due to the lack of proper access checks.
OpenCVE Enrichment
EUVD