Impact
The vulnerability is a missing authorization check in the WooCommerce POS plugin that allows an attacker to perform actions unauthorized by normal user privileges. This could include viewing, modifying, or deleting orders, and potentially manipulating the point‑of‑sale interface. The weakness corresponds to CWE‑862, “Missing Authorization.” The impact is unauthorized access to privileged functionality within the plugin, which could lead to data compromise or service disruption.
Affected Systems
The flaw affects the kilbot WooCommerce POS WordPress plugin for all releases from an unspecified baseline through version 1.7.8. Sites running WordPress that have installed this plugin at those or older versions are vulnerable. The vulnerability is not tied to any specific operating system or hosting configuration beyond the presence of the plugin.
Risk and Exploitability
The CVSS base score of 5.3 places the flaw in the moderate range, and the EPSS score of less than 1% indicates a low probability of exploitation in the wild. The vulnerability is not listed in CISA's KEV catalog, suggesting no widespread exploitation yet. The likely attack vector is a remote attacker sending crafted HTTP requests that bypass the plugin’s authorization checks, possibly targeting exposed endpoints that rely on the plugin’s functionality.
OpenCVE Enrichment
EUVD