Impact
The Music Player for WooCommerce plugin contains a missing authorization flaw that permits attackers to exploit incorrectly configured access control settings. An unauthenticated or low‑privileged user can gain unauthorized access to privileged plugin functions, potentially leading to data exposure or unauthorized configuration changes. The weakness corresponds to CWE‑862, missing authorization.
Affected Systems
WordPress sites using the codepeople Music Player for WooCommerce plugin at versions 1.5.1 or earlier are affected. The issue applies to all releases from the earliest to version 1.5.1 inclusive.
Risk and Exploitability
The CVSS score of 5.4 indicates moderate severity, while the EPSS score of less than 1% suggests that, at present, the likelihood of exploitation is low. It is not listed in the CISA KEV catalog. The vulnerability likely requires the attacker to have some authenticated access, such as a user with sufficient privileges to reach the plugin’s administrative interface, but it can be abused by leveraging inadequate role checks within the plugin.
OpenCVE Enrichment
EUVD