Impact
Missing Authorization vulnerability in the Stock Locations for WooCommerce plugin allows attackers to exploit incorrectly configured access control security levels. The flaw removes proper authorization checks, enabling any authenticated user to access or modify inventory location data that should be restricted.
Affected Systems
The vulnerability affects Fahad Mahmood Stock Locations for WooCommerce plugin versions up to and including 2.8.6. No other vendors or versions are cited in the advisory.
Risk and Exploitability
With a CVSS score of 7.1 the vulnerability is of moderate severity, while the EPSS score of less than 1% indicates a low likelihood of exploitation at this time. The issue is not part of the CISA KEV catalog. The likely attack vector is a web request to a plugin endpoint that lacks proper authorization checks, which an attacker could trigger through the site’s admin interface or via exposed WooCommerce REST API endpoints. An attacker would need access to a WordPress user account capable of reaching the vulnerable plugin, but the absence of role checks could allow even non‑administrator users to perform restricted actions.
OpenCVE Enrichment
EUVD