Impact
Missing authorization in the Free Woocommerce Product Table View plugin allows an attacker who gains access to the WordPress administration interface to delete arbitrary content such as products, posts, or pages. The flaw is a classic access‑control failure (CWE‑862), enabling unauthorized users to perform destructive actions that can lead to data loss and site downtime.
Affected Systems
WordPress sites running the BinaryCarpenter "Free Woocommerce Product Table View" plugin version 1.78 or older are affected. This includes any deployment where the plugin is installed and accessed through the standard WordPress admin interface.
Risk and Exploitability
The vulnerability scores 6.5 on the CVSS scale, indicating a moderate severity. The EPSS score of less than 1 % suggests a low probability of exploitation in the near term, and the flaw is not listed in the CISA KEV catalog. Exploitation likely requires an authenticated session with sufficient privileges to reach the plugin’s management pages; an attacker who can authenticate or who targets a site with misconfigured roles can delete content without restriction.
OpenCVE Enrichment
EUVD