Impact
The vulnerability resides in the WebToffee Product Feed for WooCommerce plugin and allows an attacker to bypass the plugin’s access control checks, gaining administrative privileges over the plugin’s settings. This broken access control flaw means that any user who can reach the plugin’s management interfaces may alter product feed parameters, generate new feeds, or expose sensitive feed data. The weakness is identified as CWE‑862, indicating a lack of proper authorization controls.
Affected Systems
The affected product is WebToffee’s Product Feed for WooCommerce plugin, versions from the earliest through 2.2.8. Any WordPress installation running this plugin within that version range is susceptible.
Risk and Exploitability
The CVSS score of 4.3 suggests a moderate level of severity, while the EPSS score of less than 1% indicates a very low likelihood of exploitation in the wild at present. The vulnerability is not listed in the CISA KEV catalog. Access control weaknesses typically require the attacker to have some form of authenticated or local access to the WordPress site; however, the specific prerequisites for exploitation are not detailed in the description, so the derived attack vector is inferred to be “local or authenticated.”
OpenCVE Enrichment
EUVD