Impact
The CartBoss WordPress plugin contains a missing authorization flaw in its cart management functions. This oversight permits an attacker to bypass intended access controls and perform unintended actions on cart data, such as viewing, modifying, or deleting items and potentially altering pricing or promotional details. The weakness is identified by CWE‑862, which represents a broken access control risk that can compromise data integrity within the affected plugin.
Affected Systems
The vulnerability applies to all CartBoss plugin installations from the earliest release through version 4.1.2. Upgrading to a later version eliminates the flaw; older releases are therefore at risk.
Risk and Exploitability
The CVSS score of 4.3 indicates a medium severity, and the EPSS score of less than 1% suggests a low likelihood of exploitation in the wild. The plugin is not listed in CISA’s KEV catalog, further supporting the notion of limited current exploitation activity. An attacker can likely discover the vulnerability by sending standard HTTP requests to the plugin’s endpoints, implying a network-based attack vector that may be triggered remotely by a user without special privileges.
OpenCVE Enrichment
EUVD