Impact
The vulnerability is a Missing Authorization flaw (CWE‑862) in the WPXPO WowStore plugin’s product‑blocks module. It permits users to exploit incorrectly configured access control security levels, potentially enabling unauthorized actions on the shop’s data.
Affected Systems
The affected software is the WordPress WowStore plugin published by WPXPO. Versions from the release series through and including 4.2.4 are impacted.
Risk and Exploitability
The CVSS score of 4.3 indicates moderate severity, and the EPSS score of less than 1% suggests low likelihood of widespread exploitation. The vulnerability is not listed in CISA’s KEV catalog. While exact attack prerequisites are not disclosed, the flaw is likely exploitable by users with administrative access or by those who can manipulate the plugin’s product‑blocks settings. Based on the description, the attack vector could involve web‑based interaction with privileged endpoints, although this is inferred rather than explicitly stated.
OpenCVE Enrichment
EUVD