Impact
A missing authorization flaw in the Sharespine Woocommerce Connector plugin allows an attacker who can exploit incorrectly configured access control levels to gain unauthorized access. This weakness corresponds to CWE-862 and can enable users without proper permissions to perform actions that should be restricted, potentially exposing sensitive store data or allowing unintended changes to plugin settings.
Affected Systems
The vulnerability affects the Sharespine Woocommerce Connector plugin, versions from the earliest released through 4.7.55. Users running any of these versions are at risk unless they upgrade or otherwise mitigate the issue.
Risk and Exploitability
The CVSS score of 4.3 indicates moderate severity. The EPSS score of less than 1% suggests a low likelihood of immediate exploitation, and the vulnerability is not listed in the CISA KEV catalog. The attack surface appears to be the web interface where incorrect role permissions are granted; the exploit requires knowledge of an existing user account that has been misconfigured to have higher privileges than intended. While no remote code execution or denial of service is described, the compromised authority could lead to data exposure or integrity violations depending on the plugin’s functionality.
OpenCVE Enrichment
EUVD