Impact
The vulnerability is a missing authorization flaw that permits any user who can access the WooCommerce product reorder interface to change the display order of products. This could be used to highlight or hide certain items, manipulate search results, or disrupt the intended product presentation, thereby affecting the user experience and potentially revenue. The weakness is identified as CWE-862.
Affected Systems
The affected system is the Vagonic Woocommerce Products Reorder Drag Drop Multiple Sort – Sortable, Rearrange Products plugin for WordPress, specifically all releases up to and including version 1.9.
Risk and Exploitability
With a CVSS score of 4.3, the severity is classified as low; the EPSS score is less than 1%, indicating a very low probability of exploitation, and the vulnerability is not listed in CISA’s KEV catalog. The attack would likely require the attacker to have access to the plugin interface, which may be reachable from the site’s front-end or admin area. Because the authorization check is missing, any user who can reach that interface may reorder products, making the flaw potentially exploitable by legitimate users with minimal effort. However, the impact is limited to cosmetic or ordering changes rather than system compromise.
OpenCVE Enrichment
EUVD