Impact
The vulnerability is a broken access control flaw, also known as missing authorization, in the FraudLabs Pro for WooCommerce plugin. An attacker can exploit incorrectly configured access control security levels to access or modify data or actions that should be restricted. This weakness is identified as CWE‑862 and allows operations that ordinarily require higher privileges, such as viewing or altering fraud detection settings, potentially compromising sensitive order information and customer data.
Affected Systems
The affected product is the FraudLabs Pro for WooCommerce plugin for WordPress, listed under the vendor FraudLabs Pro. Versions from the earliest available build through and including 2.22.11 are impacted. Any WordPress site that has this version of the plugin installed is at risk.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity, while the EPSS score of less than 1% reflects a very low likelihood of exploitation in the wild at this time. The vulnerability is not currently listed in the CISA KEV catalog, suggesting no confirmed public exploits. Attackers would need a privilege that allows them to interact with the plugin’s administrative or configuration interfaces, such as a user with administrative roles or a compromised account. Once they gain access, they could manipulate fraud rules or bypass fraud checks, potentially leading to financial loss or data exposure.
OpenCVE Enrichment
EUVD