Impact
A missing authorization flaw in the Bulk Assign Linked Products For WooCommerce plugin allows users to invoke functionality that the code does not properly restrict by access control lists. The vulnerability is classified as a CWE‑862 weakness and carries a CVSS score of 5.3, indicating moderate severity. It can enable an attacker to manipulate linked product assignments, potentially altering product relationships or store configuration without proper authorization.
Affected Systems
The flaw affects all installations of the WordPress plugin Bulk Assign Linked Products For WooCommerce version 2.1 and earlier, supplied by the vendor vinodvaswani9. The vulnerability spans all WordPress sites that have the plugin installed and have not upgraded beyond the stated maximum version.
Risk and Exploitability
The EPSS score of less than 1% indicates a very low current exploit probability, and the vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is via authenticated HTTP requests to the plugin’s administrative endpoints; an attacker who can authenticate to the WordPress site (or, if no restrictions exist, possibly through an unauthenticated request that targets the plugin) can exploit the broken access control to alter product linkings. The risk is therefore a moderate impact to integrity of the store’s product associations rather than a full remote code execution.
OpenCVE Enrichment
EUVD