Impact
Keylor Mendoza WC Pickup Store for WordPress contains a Missing Authorization flaw that permits users to alter plugin settings without proper privilege checks. This weakness is defined as CWE-862 and enables an attacker to modify configuration values, potentially leading to unauthorized changes in store pickup behavior.
Affected Systems
The vulnerability affects any WordPress site that has the WC Pickup Store plugin version 1.8.9 or earlier installed. These sites may be running on any WordPress version that supports the plugin.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity, while the EPSS score of less than 1% suggests a very low probability of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is a web-based interaction through the plugin’s settings interface, exploiting incorrectly configured access control levels. No evidence of remote code execution or kernel level impact is provided.
OpenCVE Enrichment
EUVD