Impact
The vulnerability is a CSRF flaw that permits attackers to force authenticated users to submit requests that modify product quantity limits in the WooCommerce plugin. An attacker could change the minimum, maximum, or step values without authorization, potentially disrupting the store’s pricing and purchasing policies. This flaw falls under the Cross‑Site Request Forgery weakness (CWE‑352).
Affected Systems
Affected products are the WPFactory Min Max Step Quantity Limits Manager for WooCommerce plugin, any version from the initial release through 5.1.0. WordPress sites running this plugin and its compatibility package are vulnerable. No specific operating system or PHP version is noted beyond the plugin level.
Risk and Exploitability
The calculated CVSS score of 4.3 indicates low overall risk, and the EPSS score of less than one percent suggests it is unlikely to be actively exploited at present. The vulnerability is not currently listed in the CISA KEV catalog. Exploitation requires a victim who is logged in to the WordPress admin area and may be achieved by sending a crafted request or embedding a link within a third‑party site that a user visits while authenticated.
OpenCVE Enrichment
EUVD