Impact
The vulnerability is a missing authorization flaw that allows an attacker to change settings within the Shopify to WooCommerce Migration plugin. This lack of access control can enable unauthorized users to alter migration parameters and potentially compromise site configuration, resulting in a loss of control over data transfer processes.
Affected Systems
WordPress sites that use the Shopify to WooCommerce Migration plugin in versions n/a through 1.3.0 are affected. The plugin is issued by Plugin Devs and is commonly installed on WordPress installations that migrate e-commerce data between Shopify and WooCommerce.
Risk and Exploitability
The CVSS score of 6.5 indicates a medium severity risk, while the EPSS score of less than 1% suggests a low probability of exploitation. The vulnerability is not listed in CISA’s KEV catalog. Attackers would need to leverage an authenticated session or exploit incorrect role configuration; any user with sufficient privileges could abuse this flaw to modify plugin settings. Although the likelihood of exploitation is low, the impact could be significant if the plugin configuration is altered during a migration.
OpenCVE Enrichment
EUVD